CVE-2014-2020: PHP

Medium severity, CVSS 5.0. EPSS: 2.5% chance of exploitation in the next 30 days.

ext/gd/gd.c in PHP 5.5.x before 5.5.9 does not check data types, which might allow remote attackers to obtain sensitive information by using a (1) string or (2) array data type in place of a numeric data type, as demonstrated by an imagecrop function call with a string for the x dimension value, a different vulnerability than CVE-2013-7226.

Affected products

  • PHP PHP: up to and including 5.5.8; version 5.5.0 only; version 5.5.1 only; version 5.5.2 only; version 5.5.3 only; version 5.5.4 only; …

Published 2014-02-18. Last modified 2026-06-17.