Description
When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
Low
Affected products
- Canonical / Ubuntu Linux19.04 – 19.04
- Canonical / Ubuntu Linux12.04 – 12.04
- Canonical / Ubuntu Linux14.04 – 14.04
- Canonical / Ubuntu Linux16.04 – 16.04
- Canonical / Ubuntu Linux18.04 – 18.04
- debian / debian_linux8.0 – 8.0
- debian / debian_linux10.0 – 10.0
- debian / debian_linux9.0 – 9.0
- fedoraproject / fedora31 – 31
- fedoraproject / fedora30 – 30
- openSUSE / Leap15.1 – 15.1
- php / php7.4.0 – 7.4.0
- php / php7.2.0 – 7.2.26
- PHP Group / PHP7.4.x – 7.4.1
- PHP Group / PHP7.3.x – 7.3.13
- PHP Group / PHP7.2.x – 7.2.26
- tenable / Security Center5.19.0
References
- MISChttps://bugs.php.net/bug.php?id=78793
- MAILING_LISThttps://lists.debian.org/debian-lts-announce/2019/12/msg00034.html
- MISChttps://security.netapp.com/advisory/ntap-20200103-0002/
- MAILING_LISThttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N7GCOAE6KVHYJ3UQ4KLPLTGSLX6IRVRN/
- MAILING_LISThttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XWRQPYXVG43Q7DXMXH6UVWMKWGUW552F/
- VENDOR_ADVISORYhttps://usn.ubuntu.com/4239-1/
- MAILING_LISThttp://lists.opensuse.org/opensuse-security-announce/2020-01/msg00036.html
- MAILING_LISThttps://seclists.org/bugtraq/2020/Feb/27
- VENDOR_ADVISORYhttps://www.debian.org/security/2020/dsa-4626
- VENDOR_ADVISORYhttps://www.debian.org/security/2020/dsa-4628
- MAILING_LISThttps://seclists.org/bugtraq/2020/Feb/31
- MAILING_LISThttps://seclists.org/bugtraq/2021/Jan/3
- MISChttps://www.tenable.com/security/tns-2021-14
Updated 5m ago · 8 sources