It was found that output function from gd_gif_out.c causes out-of-bounds access of the masks array when ctx->cur_bits becomes a negative number. PHP bug: https://bugs.php.net/bug.php?id=72519 PHP fix: https://git.php.net/?p=php-src.git;a=blobdiff;f=ext/gd/libgd/gd_gif_out.c;h=0178dd9741dc4d9f0a956b99670a5838a2f7b22b;hp=14045385ab834abe2c3183f48a6a32dd3a2a19f2;hb=a48f64c403b05da244cfd30399bffd53e910a440;hpb=210222928e52b95827a0b5e4a987303233597f89
Created gd tracking bugs for this issue: Affects: fedora-all [bug 1359839]
Created php tracking bugs for this issue: Affects: fedora-all [bug 1359837]
Out-of-bounds read of a global buffer. I can't see any real impact on security here.