CVE-2013-7328: PHP

Medium severity, CVSS 5.8. EPSS: 1.5% chance of exploitation in the next 30 days.

Multiple integer signedness errors in the gdImageCrop function in ext/gd/gd.c in PHP 5.5.x before 5.5.9 allow remote attackers to cause a denial of service (application crash) or obtain sensitive information via an imagecrop function call with a negative value for the (1) x or (2) y dimension, a different vulnerability than CVE-2013-7226.

Affected products

  • PHP PHP: version 5.5.0 only; version 5.5.1 only; version 5.5.2 only; version 5.5.3 only; version 5.5.4 only; version 5.5.5 only; …

Published 2014-02-18. Last modified 2026-06-17.