exif.c in PHP before 4.3.11 allows remote attackers to cause a denial of service (memory consumption and crash) via an EXIF header with a large IFD nesting level, which causes significant stack recursion.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Php | — | Apply OS X security update 2005-006 | Dec 16, 2011 | Apr 14, 2005 |
| Gentoo Linux | — | Upgrade dev-php/php-cgi.Upgrade dev-php/mod_php.Upgrade dev-php/php. | Oct 30, 2017 | Apr 14, 2005 |
| Php | — | Upgrade to PHP version 4.3.11 | Oct 1, 2012 | Apr 14, 2005 |
| Suse | — | Upgrade php4-sysvshmUpgrade php4-develUpgrade php4-imapUpgrade php4-fastcgiUpgrade apache2-mod_php4Upgrade mod_php4-servletUpgrade php4-exifUpgrade php4-sessionUpgrade php4-mysqlUpgrade php4-pearUpgrade apache-mod_php4Upgrade mod_php4-core | Feb 17, 2015 | Apr 14, 2005 |
| Ubuntu | — | Upgrade libapache2-mod-php4 | Nov 8, 2024 | Apr 14, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub