exif.c in PHP before 4.3.11 allows remote attackers to cause a denial of service (memory consumption and crash) via an EXIF header with a large IFD nesting level, which causes significant stack recursion.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Php | — | Apply OS X security update 2005-006 | Dec 16, 2011 | Apr 14, 2005 |
| Gentoo Linux | — | Upgrade dev-php/php.Upgrade dev-php/php-cgi.Upgrade dev-php/mod_php. | Oct 30, 2017 | Apr 14, 2005 |
| Php | — | Upgrade to PHP version 4.3.11 | Oct 1, 2012 | Apr 14, 2005 |
| Suse | — | Upgrade php4-sessionUpgrade php4-exifUpgrade mod_php4-servletUpgrade php4-fastcgiUpgrade php4-sysvshmUpgrade php4-imapUpgrade apache2-mod_php4Upgrade php4-develUpgrade php4-pearUpgrade php4-mysqlUpgrade mod_php4-coreUpgrade apache-mod_php4 | Feb 17, 2015 | Apr 14, 2005 |
| Ubuntu | — | Upgrade libapache2-mod-php4 | Nov 8, 2024 | Apr 14, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub