CVE-2017-7890: PHP
Medium severity, CVSS 6.5. EPSS: 3.4% chance of exploitation in the next 30 days.
The GIF decoding function gdImageCreateFromGifCtx in gd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP before 5.6.31 and 7.x before 7.1.7, does not zero colorMap arrays before use. A specially crafted GIF image could use the uninitialized tables to read ~700 bytes from the top of the stack, potentially disclosing sensitive information.
Affected products
- PHP PHP: up to and including 5.6.30; version 7.0.0 only; version 7.0.1 only; version 7.0.2 only; version 7.0.3 only; version 7.0.4 only; …
Published 2017-08-02. Last modified 2026-06-17.