Gentoo Linux Security Advisory GLSA 200710-02 – Several vulnerabilities were found in PHP. Mattias Bengtsson and Philip Olausson reported integer overflows in the gdImageCreate() and gdImageCreateTrueColor() functions of the GD library which can cause heap-based buffer overflows. Gerhard Wagner discovered an integer overflow in the chunk_split() function that can lead to a heap-based buffer overflow. Its incomplete fix caused incorrect buffer size calculation due to precision loss, also resulting in a possible heap-based buffer overflow. A buffer overflow in the sqlite_decode_binary() of the SQLite extension found by Stefan Esser that was addressed in PHP 5.2.1 was not fixed correctly. Versions less than 5.2.4_p20070914-r2 are affected.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/59895/glsa-200710-02.txt
Source: https://packetstormsecurity.com/files/59895/Gentoo-Linux-Security-Advisory-200710-2.html

