An issue was discovered in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. exif_read_data in ext/exif/exif.c has an out-of-bounds read for crafted JPEG data because exif_iif_add_value mishandles the case of a MakerNote that lacks a final '\0' character.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade php7 | Oct 1, 2024 | Apr 29, 2018 |
| Amazon_linux | — | Upgrade php56Upgrade php71Upgrade php70 | May 11, 2018 | Apr 29, 2018 |
| Debian | — | Upgrade php7.0 | Jul 7, 2018 | Apr 29, 2018 |
| Gentoo Linux | — | Upgrade dev-lang/php. | Dec 3, 2018 | Apr 29, 2018 |
| Oracle Solaris | — | Upgrade web/php-71 to version 7.1.17-0.175.3.33.0.4.0 on Solaris 11.3Upgrade web/php-56 to version 5.6.36-0.175.3.33.0.4.0 on Solaris 11.3 | Jun 18, 2018 | Apr 29, 2018 |
| Php | — | Upgrade to PHP version 7.2.5Upgrade to PHP version 5.6.36Upgrade to PHP version 7.0.30Upgrade to PHP version 7.1.17 | Jun 11, 2018 | Apr 29, 2018 |
| Ubuntu | — | Upgrade libapache2-mod-php7.1Upgrade php7.1-cliUpgrade php5-cliUpgrade php7.2-cgiUpgrade php7.1-fpmUpgrade libapache2-mod-php7.2Upgrade php5-cgiUpgrade php7.0-cgiUpgrade php7.1-cgiUpgrade php5-fpmUpgrade libapache2-mod-php5Upgrade php7.2-fpmUpgrade php7.0-fpmUpgrade php7.0-cliUpgrade libapache2-mod-php7.0Upgrade php7.2-cli | May 23, 2018 | Apr 29, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub