Vulnerability record · CVE-2019-6977 · published 27 January 2019
CVE-2019-6977: LibGD gdImageColorMatch heap buffer overflow via PHP imagecolormatch
Libgd · Libgd
gdImageColorMatch in LibGD 2.2.5, reached through PHP's imagecolormatch function, contains a heap-based buffer overflow (CWE-787 out-of-bounds write). Crafted image data passed to imagecolormatch can corrupt heap memory, and the flaw affects PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1.
Description
gdImageColorMatch in gd_color_match.c in the GD Graphics Library (aka LibGD) 2.2.5, as used in the imagecolormatch function in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1, has a heap-based buffer overflow. This can be exploited by an attacker who is able to trigger imagecolormatch calls with crafted image data.
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityHigh CVSS (8.8), very high EPSS, and public exploit references make this a serious memory-corruption flaw, though it requires user interaction and is not in KEV.
What it is
gdImageColorMatch in LibGD 2.2.5, reached through PHP's imagecolormatch function, contains a heap-based buffer overflow (CWE-787 out-of-bounds write). Crafted image data passed to imagecolormatch can corrupt heap memory, and the flaw affects PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1.
Impact
An attacker can write out of bounds on the heap, which may lead to memory corruption, denial of service, or code execution in the context of the affected process. The CVSS 3.0 vector rates confidentiality, integrity, and availability impact as high.
Attack surface
The vulnerability is network-reachable (AV:N) with no privileges required (PR:N), but exploitation requires user interaction (UI:R), consistent with an application processing attacker-supplied image data through imagecolormatch. Any service or script that calls imagecolormatch on untrusted images is in scope.
Exploitation
CVE-2019-6977 is not listed in CISA KEV, but EPSS is very high at 0.71496 (99.385th percentile), and references include an Exploit-tagged PHP bug report and an Exploit-DB entry, indicating public exploit material exists.
What to do
- Patch PHP to 5.6.40, 7.1.26, 7.2.14, or 7.3.1 or later, and update bundled or system LibGD to a fixed release.
- Apply vendor advisories for Debian, Ubuntu, Red Hat, Fedora, openSUSE, Gentoo, and NetApp products that ship the affected library.
- Avoid calling imagecolormatch on untrusted or user-supplied image data until patched.
- Validate and restrict image uploads and processing paths, and run image-processing services with least privilege.
Detection
- Monitor for crashes or abnormal process termination in PHP or LibGD image-processing workloads.
- Audit application code and logs for imagecolormatch calls handling externally supplied images.
- Use memory-corruption detection such as ASAN or hardened allocators in test environments to catch out-of-bounds writes.
- Track exploit attempts against image upload or processing endpoints using known public PoC patterns.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-6977 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-6977), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.