← Vulnerability feed

Vulnerability record · CVE-2019-6977 · published 27 January 2019

CVE-2019-6977: LibGD gdImageColorMatch heap buffer overflow via PHP imagecolormatch

Libgd · Libgd

gdImageColorMatch in LibGD 2.2.5, reached through PHP's imagecolormatch function, contains a heap-based buffer overflow (CWE-787 out-of-bounds write). Crafted image data passed to imagecolormatch can corrupt heap memory, and the flaw affects PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1.

8.8 CVSS 3.0 High EPSS 71% · top 0.6% CWE-787 · Out-of-bounds write
8.8CVSS 3.0 base score, v2 6.8
71%EPSS exploitation probability, 30 days
NoNot in CISA KEV
5Affected product versions listed by NVD
38References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

gdImageColorMatch in gd_color_match.c in the GD Graphics Library (aka LibGD) 2.2.5, as used in the imagecolormatch function in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1, has a heap-based buffer overflow. This can be exploited by an attacker who is able to trigger imagecolormatch calls with crafted image data.

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityHigh CVSS (8.8), very high EPSS, and public exploit references make this a serious memory-corruption flaw, though it requires user interaction and is not in KEV.

What it is

gdImageColorMatch in LibGD 2.2.5, reached through PHP's imagecolormatch function, contains a heap-based buffer overflow (CWE-787 out-of-bounds write). Crafted image data passed to imagecolormatch can corrupt heap memory, and the flaw affects PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1.

Impact

An attacker can write out of bounds on the heap, which may lead to memory corruption, denial of service, or code execution in the context of the affected process. The CVSS 3.0 vector rates confidentiality, integrity, and availability impact as high.

Attack surface

The vulnerability is network-reachable (AV:N) with no privileges required (PR:N), but exploitation requires user interaction (UI:R), consistent with an application processing attacker-supplied image data through imagecolormatch. Any service or script that calls imagecolormatch on untrusted images is in scope.

Exploitation

CVE-2019-6977 is not listed in CISA KEV, but EPSS is very high at 0.71496 (99.385th percentile), and references include an Exploit-tagged PHP bug report and an Exploit-DB entry, indicating public exploit material exists.

What to do

  • Patch PHP to 5.6.40, 7.1.26, 7.2.14, or 7.3.1 or later, and update bundled or system LibGD to a fixed release.
  • Apply vendor advisories for Debian, Ubuntu, Red Hat, Fedora, openSUSE, Gentoo, and NetApp products that ship the affected library.
  • Avoid calling imagecolormatch on untrusted or user-supplied image data until patched.
  • Validate and restrict image uploads and processing paths, and run image-processing services with least privilege.

Detection

  • Monitor for crashes or abnormal process termination in PHP or LibGD image-processing workloads.
  • Audit application code and logs for imagecolormatch calls handling externally supplied images.
  • Use memory-corruption detection such as ASAN or hardened allocators in test environments to catch out-of-bounds writes.
  • Track exploit attempts against image upload or processing endpoints using known public PoC patterns.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00025.html
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00031.html
http://packetstormsecurity.com/files/152459/PHP-7.2-imagecolormatch-Out-Of-Band-Heap-Write.html
http://php.net/ChangeLog-5.php Release NotesVendor Advisory
http://php.net/ChangeLog-7.php Release NotesVendor Advisory
http://www.securityfocus.com/bid/106731 Third Party AdvisoryVDB Entry
https://access.redhat.com/errata/RHSA-2019:2519
https://access.redhat.com/errata/RHSA-2019:3299
https://bugs.php.net/bug.php?id=77270 ExploitIssue TrackingMailing ListVendor Advisory
https://lists.debian.org/debian-lts-announce/2019/01/msg00028.html Mailing ListThird Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3CZ2QADQTKRHTGB2AHD7J4Q
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3WRUPZVT2MWFUEMVGTRAGDO
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TEYUUOW75YD3DENIPYMO263
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TTXSLRZI5BCQT3H5KALG3DH
https://security.gentoo.org/glsa/201903-18 Third Party Advisory
https://security.netapp.com/advisory/ntap-20190315-0003/ PatchThird Party Advisory
https://usn.ubuntu.com/3900-1/ Third Party Advisory
https://www.debian.org/security/2019/dsa-4384 Third Party Advisory
https://www.exploit-db.com/exploits/46677/
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00025.html
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00031.html
http://packetstormsecurity.com/files/152459/PHP-7.2-imagecolormatch-Out-Of-Band-Heap-Write.html
http://php.net/ChangeLog-5.php Release NotesVendor Advisory
http://php.net/ChangeLog-7.php Release NotesVendor Advisory
http://www.securityfocus.com/bid/106731 Third Party AdvisoryVDB Entry
https://access.redhat.com/errata/RHSA-2019:2519
https://access.redhat.com/errata/RHSA-2019:3299
https://bugs.php.net/bug.php?id=77270 ExploitIssue TrackingMailing ListVendor Advisory
https://lists.debian.org/debian-lts-announce/2019/01/msg00028.html Mailing ListThird Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3CZ2QADQTKRHTGB2AHD7J4Q
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3WRUPZVT2MWFUEMVGTRAGDO
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TEYUUOW75YD3DENIPYMO263
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TTXSLRZI5BCQT3H5KALG3DH
https://security.gentoo.org/glsa/201903-18 Third Party Advisory
https://security.netapp.com/advisory/ntap-20190315-0003/ PatchThird Party Advisory
https://usn.ubuntu.com/3900-1/ Third Party Advisory
https://www.debian.org/security/2019/dsa-4384 Third Party Advisory
https://www.exploit-db.com/exploits/46677/

Track CVE-2019-6977 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-32433Erlang/OTP SSH server missing authentication allows remote code executionErlang/OTP SSH servers before OTP-27.3.3, OTP-26.2.5.11 and OTP-25.3.2.20 mishandle SSH protocol messages, letting an unauthenticated attacker execut…KEVEPSS 99%analysed10.0CVE-2025-24201Apple WebKit out-of-bounds write allows sandbox escapeCVE-2025-24201 is an out-of-bounds write in Apple's WebKit that was addressed with improved checks. Maliciously crafted web content may break out of …KEVEPSS 3.8%analysed10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.8CVE-2026-24061GNU Inetutils telnetd argument injection allows remote auth bypasstelnetd in GNU Inetutils through 2.7 fails to sanitize the USER environment variable, so a value such as "-f root" is passed as an argument to login …KEVEPSS 99%analysed9.8CVE-2025-39682Linux kernel TLS zero-length record handling flaw on rx_listThe Linux kernel TLS receive path mishandles zero-length records that arrive from the rx_list, breaking the assumption that a record type change cann…KEVEPSS 2.9%analysed9.8CVE-2025-24813Apache Tomcat Default Servlet path equivalence enables RCE and file disclosureApache Tomcat mishandles path equivalence for names containing an internal dot, letting a remote unauthenticated attacker write files through the Def…KEVEPSS 100%analysed9.8CVE-2024-9680Mozilla Firefox and Thunderbird use-after-free in Animation timelinesA use-after-free flaw in Animation timelines allows an attacker to execute code in the content process of Firefox and Thunderbird. Mozilla reports ex…KEVEPSS 23%analysed9.8CVE-2024-4577PHP-CGI on Windows argument injection leads to remote code executionPHP-CGI on Windows can misinterpret characters in the command line passed to Win32 API functions when certain code pages are configured, due to Windo…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2019-6977), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.