CVE-2014-5120
Summary
| CVE | CVE-2014-5120 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-08-23 01:55:02 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | gd_ctx.c in the GD component in PHP 5.4.x before 5.4.32 and 5.5.x before 5.5.16 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to overwrite arbitrary files via crafted input to an application that calls the (1) imagegd, (2) imagegd2, (3) imagegif, (4) imagejpeg, (5) imagepng, (6) imagewbmp, or (7) imagewebp function. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:N/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Php | Php | 5.4.0 | All | All | All |
| Application | Php | Php | 5.4.0 | beta2 | All | All |
| Application | Php | Php | 5.4.0 | beta2 | 32-bit | All |
| Application | Php | Php | 5.4.0 | rc2 | All | All |
| Application | Php | Php | 5.4.1 | All | All | All |
| Application | Php | Php | 5.4.10 | All | All | All |
| Application | Php | Php | 5.4.11 | All | All | All |
| Application | Php | Php | 5.4.12 | All | All | All |
| Application | Php | Php | 5.4.12 | rc1 | All | All |
| Application | Php | Php | 5.4.12 | rc2 | All | All |
| Application | Php | Php | 5.4.13 | All | All | All |
| Application | Php | Php | 5.4.13 | rc1 | All | All |
| Application | Php | Php | 5.4.14 | All | All | All |
| Application | Php | Php | 5.4.14 | rc1 | All | All |
| Application | Php | Php | 5.4.15 | All | All | All |
| Application | Php | Php | 5.4.15 | rc1 | All | All |
| Application | Php | Php | 5.4.16 | rc1 | All | All |
| Application | Php | Php | 5.4.17 | All | All | All |
| Application | Php | Php | 5.4.18 | All | All | All |
| Application | Php | Php | 5.4.19 | All | All | All |
| Application | Php | Php | 5.4.2 | All | All | All |
| Application | Php | Php | 5.4.20 | All | All | All |
| Application | Php | Php | 5.4.21 | All | All | All |
| Application | Php | Php | 5.4.22 | All | All | All |
| Application | Php | Php | 5.4.23 | All | All | All |
| Application | Php | Php | 5.4.24 | All | All | All |
| Application | Php | Php | 5.4.25 | All | All | All |
| Application | Php | Php | 5.4.26 | All | All | All |
| Application | Php | Php | 5.4.27 | All | All | All |
| Application | Php | Php | 5.4.28 | All | All | All |
| Application | Php | Php | 5.4.29 | All | All | All |
| Application | Php | Php | 5.4.3 | All | All | All |
| Application | Php | Php | 5.4.30 | All | All | All |
| Application | Php | Php | 5.4.31 | All | All | All |
| Application | Php | Php | 5.4.4 | All | All | All |
| Application | Php | Php | 5.4.5 | All | All | All |
| Application | Php | Php | 5.4.6 | All | All | All |
| Application | Php | Php | 5.4.7 | All | All | All |
| Application | Php | Php | 5.4.8 | All | All | All |
| Application | Php | Php | 5.4.9 | All | All | All |
| Application | Php | Php | 5.5.0 | All | All | All |
| Application | Php | Php | 5.5.0 | alpha1 | All | All |
| Application | Php | Php | 5.5.0 | alpha2 | All | All |
| Application | Php | Php | 5.5.0 | alpha3 | All | All |
| Application | Php | Php | 5.5.0 | alpha4 | All | All |
| Application | Php | Php | 5.5.0 | alpha5 | All | All |
| Application | Php | Php | 5.5.0 | alpha6 | All | All |
| Application | Php | Php | 5.5.0 | beta1 | All | All |
| Application | Php | Php | 5.5.0 | beta2 | All | All |
| Application | Php | Php | 5.5.0 | beta3 | All | All |
| Application | Php | Php | 5.5.0 | beta4 | All | All |
| Application | Php | Php | 5.5.0 | rc1 | All | All |
| Application | Php | Php | 5.5.0 | rc2 | All | All |
| Application | Php | Php | 5.5.1 | All | All | All |
| Application | Php | Php | 5.5.10 | All | All | All |
| Application | Php | Php | 5.5.11 | All | All | All |
| Application | Php | Php | 5.5.12 | All | All | All |
| Application | Php | Php | 5.5.13 | All | All | All |
| Application | Php | Php | 5.5.14 | All | All | All |
| Application | Php | Php | 5.5.15 | All | All | All |
| Application | Php | Php | 5.5.2 | All | All | All |
| Application | Php | Php | 5.5.3 | All | All | All |
| Application | Php | Php | 5.5.4 | All | All | All |
| Application | Php | Php | 5.5.5 | All | All | All |
| Application | Php | Php | 5.5.6 | All | All | All |
| Application | Php | Php | 5.5.7 | All | All | All |
| Application | Php | Php | 5.5.8 | All | All | All |
| Application | Php | Php | 5.5.9 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| About the security content of OS X Yosemite v10.10.3 and Security Update 2015-004 - Apple Support | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | |
| Oracle Bulletin Board Update - January 2015 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | |
| APPLE-SA-2015-04-08-2 OS X 10.10.3 and Security Update 2015-004 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| PHP :: Sec Bug #67730 :: CVE-2014-5120 Null byte injection possible with imagexxx functions | af854a3a-2127-422b-91ae-364da2661108 | bugs.php.net | Vendor Advisory |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| openSUSE-SU-2014:1133-1: moderate: php5 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| PHP: PHP 5 ChangeLog | af854a3a-2127-422b-91ae-364da2661108 | php.net | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.