Description
gd_ctx.c in the GD component in PHP 5.4.x before 5.4.32 and 5.5.x before 5.5.16 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to overwrite arbitrary files via crafted input to an application that calls the (1) imagegd, (2) imagegd2, (3) imagegif, (4) imagejpeg, (5) imagepng, (6) imagewbmp, or (7) imagewebp function.
Remediation
References
Related Vulnerabilities
WordPress Plugin Rucy Cross-Site Request Forgery (0.4.4)
Python Integer Overflow or Wraparound Vulnerability (CVE-2008-3143)
WordPress Plugin Falang multilanguage for WordPress Cross-Site Scripting (1.3.17)
Liferay Portal Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2022-42129)
XWikiplatform Missing Authorization Vulnerability (CVE-2024-31987)