CVE-2019-11038 - CVE House
Back to Database
Status published Low CVE-2019-11038

Uninitialized read in gdImageCreateFromXbm

Vulnerability Description

When using the gdImageCreateFromXbm() function in the GD Graphics Library (aka LibGD) 2.2.5, as used in the PHP GD extension in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6, it is possible to supply data that will cause the function to use the value of uninitialized variable. This may lead to disclosing contents of the stack that has been left there by previous code.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-11038

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • By chamal dot desilva at gmail dot com

Affected Vendor

Affected Software

PHP
Vulnerable Versions:
7.1.x < 7.1.30, 7.2.x < 7.2.19, 7.3.x < 7.3.6

Timeline

Official Publish: June 18th, 2019
Last Modified: September 16th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.