CVE-2013-7327: Canonical Ubuntu Linux

Medium severity, CVSS 6.8. EPSS: 2.7% chance of exploitation in the next 30 days.

The gdImageCrop function in ext/gd/gd.c in PHP 5.5.x before 5.5.9 does not check return values, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via invalid imagecrop arguments that lead to use of a NULL pointer as a return value, a different vulnerability than CVE-2013-7226.

Affected products

  • Canonical Ubuntu Linux: version 10.04 only; version 12.04 only; version 12.10 only; version 13.10 only
  • PHP PHP: up to and including 5.5.8; version 5.5.0 only; version 5.5.1 only; version 5.5.2 only; version 5.5.3 only; version 5.5.4 only; …

Published 2014-02-18. Last modified 2026-06-17.