CVE-2014-2497: Canonical Ubuntu Linux

Medium severity, CVSS 4.3. EPSS: 20.3% chance of exploitation in the next 30 days.

The gdImageCreateFromXpm function in gdxpm.c in libgd, as used in PHP 5.4.26 and earlier, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted color table in an XPM file.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.10 only; version 16.04 only
  • Debian Debian Linux: version 7.0 only; version 8.0 only
  • Oracle Solaris: version 11.2 only
  • PHP PHP: before 5.4.32 (fixed in 5.4.32); from 5.5.0, before 5.5.16 (fixed in 5.5.16)
  • Red Hat Enterprise Linux Desktop: version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Eus: version 6.5 only; version 7.3 only; version 7.4 only; version 7.5 only; version 7.6 only; version 7.7 only
  • Red Hat Enterprise Linux Server: version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Server Aus: version 6.5 only; version 7.3 only; version 7.6 only
  • Red Hat Enterprise Linux Server Tus: version 6.5 only; version 7.3 only; version 7.6 only; version 7.7 only
  • Red Hat Enterprise Linux Workstation: version 6.0 only; version 7.0 only
  • Suse Linux Enterprise Server: version 11 only
  • Suse Linux Enterprise Software Development Kit: version 11 only

Published 2014-03-21. Last modified 2026-06-17.