Buffer overflow in the exif_read_data function in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to execute arbitrary code via a long section name in an image file.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Php | — | Apply OS X security update 2005-001 | Dec 16, 2011 | Jan 10, 2005 |
| Freebsd | — | Upgrade php4-dtcUpgrade mod_php5Upgrade php4-cliUpgrade php4Upgrade mod_php4Upgrade php4-cgiUpgrade php5-cgiUpgrade php4-nmsUpgrade mod_php4-twigUpgrade php5Upgrade php5-cliUpgrade php4-hordeUpgrade mod_php | Dec 10, 2025 | Dec 17, 2004 |
| Gentoo Linux | — | Upgrade dev-php/php-cgi.Upgrade dev-php/php.Upgrade dev-php/mod_php. | Oct 30, 2017 | Jan 10, 2005 |
| Hpsmh | — | Upgrade to the latest version of HP System Management Homepage | Oct 13, 2015 | Jan 10, 2005 |
| Php | — | Upgrade to PHP version 5.0.3Upgrade to PHP version 4.3.10 | Oct 1, 2012 | Jan 10, 2005 |
| Suse | — | Upgrade php4-develUpgrade mod_php4-servletUpgrade php4-pearUpgrade php4-sysvshmUpgrade php4-mysqlUpgrade php4-exifUpgrade apache-mod_php4Upgrade apache2-mod_php4Upgrade php4-imapUpgrade php4-sessionUpgrade php4-fastcgiUpgrade mod_php4-core | Feb 17, 2015 | Jan 10, 2005 |
| Ubuntu | — | Upgrade php4 | Nov 8, 2024 | Jan 10, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub