A heap-based buffer overflow exists in the gdImageColorMatch function in gd_color_match.c of the GD Graphics Library (LibGD) version 2.2.5. This vulnerability is exposed via the imagecolormatch function in PHP (prior to 5.6.40, 7.1.26, 7.2.14, and 7.3.1) when called with crafted image data. The vulnerable function fails to properly validate buffer boundaries when processing image data, leading to a potential overflow on the heap.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is a multi-case PHP exploitation research corpus rather than a single exploit. It contains five exploit environments: RCE-CVE-2022-31626, RCE-CVE-2024-2961, SBE-CVE-2019-6977, RCE-N1CTF-php_master, and RCE-SecurinetsCTF-I_hate_php, plus a large Reproduce/ tree for building vulnerable images, validating mitigations, and benchmarking two defensive patch sets (hashtable and refcount guards). Core exploit capability: each main exploit script achieves memory disclosure followed by corruption of Zend/PHP internal structures to redirect execution to system/popen/destructor gadgets, ultimately executing shell commands and exposing output through a file such as 1.php. The payloads are basic hardcoded shell commands (uname/date), so maturity is OPERATIONAL rather than framework-grade weaponized. Per-case structure: - RCE-CVE-2022-31626: Python exploit against a PHP page that accepts MySQL connection parameters and JSON input. The environment includes a rogue_sql_server.py listener on TCP/3306 to emulate a MySQL server and induce the vulnerable state. The exploit performs two leaks (heap and zend), probes candidate libc offsets, then writes a command string and pivots execution to libc system(). - RCE-CVE-2024-2961: Python exploit against a PHP page calling md5_file() on attacker-controlled php://filter/iconv input. It abuses the glibc ISO-2022-CN-EXT conversion path to obtain heap/zend leaks and then corrupts structures to call system(). - RCE-N1CTF-php_master: Includes a full vulnerable PHP web app (DataForm) with session-backed serialized state and compression/inflate operations. The exploit drives the /dataform endpoint through add/insert/append/delete actions, leaks heap data from error snapshots, constructs fake Zend structures, and brute-probes libc deltas until command execution succeeds. - RCE-SecurinetsCTF-I_hate_php: Includes a custom PHP extension (juice.so) implementing xorBMP(). The exploit sends crafted base64 BMPs and JSON layout data to trigger memory corruption, derives heap and PHP text base addresses from returned BMP data, forges a HashTable/frame, and redirects execution to zif_popen. - SBE-CVE-2019-6977: A PHP-only sandbox-bypass / info-leak / code-exec chain. The target script itself contains the exploitation primitives, exposing ?leak and ?pwn modes. The Python wrapper fetches leaked addresses, computes a gadget address, triggers the overwrite, and polls 1.php for command output. Repository support content: - Dockerfiles for each case build pinned PHP source revisions with custom hardening/experimental patches applied. - Reproduce/Patch-hashtable and Reproduce/Patch-refcnt contain mitigation patches, verification harnesses, and benchmark Dockerfiles. These are not exploits; they are defensive evaluation artifacts showing whether the included exploits still succeed after patching. - Reproduce/run_reliability_100.sh and run_performance_tests.sh automate repeated exploit runs and performance measurements. - Misc/static_analysis.ql and patch files document research into allocator/hashtable/refcount hardening. Overall purpose: to provide reproducible exploit demonstrations for several PHP memory-corruption cases and challenge-derived targets, alongside experimental mitigations and benchmarking infrastructure. The code is clearly exploit-oriented, not merely detection, and the included web endpoints, local FastCGI backends, rogue MySQL service, and output files are all fingerprintable operational artifacts.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.