CVE-2014-5120: PHP

Medium severity, CVSS 6.4. EPSS: 16.9% chance of exploitation in the next 30 days.

gd_ctx.c in the GD component in PHP 5.4.x before 5.4.32 and 5.5.x before 5.5.16 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to overwrite arbitrary files via crafted input to an application that calls the (1) imagegd, (2) imagegd2, (3) imagegif, (4) imagejpeg, (5) imagepng, (6) imagewbmp, or (7) imagewebp function.

Affected products

  • PHP PHP: version 5.4.0 only; version 5.4.1 only; version 5.4.2 only; version 5.4.3 only; version 5.4.4 only; version 5.4.5 only; …

Published 2014-08-23. Last modified 2026-06-17.