ISOMAN

CVE

CVE-2019-11041

When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.31, 7.2.x below 7.2.21 and 7.3.x below 7.3.8 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.

Severity
HIGH
CVSS
7.1
Published
Modified

Linked Releases

References

  1. http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00019.html
  2. http://seclists.org/fulldisclosure/2019/Oct/15
  3. http://seclists.org/fulldisclosure/2019/Oct/55
  4. https://access.redhat.com/errata/RHSA-2019:3299
  5. https://bugs.php.net/bug.php?id=78222
  6. https://lists.debian.org/debian-lts-announce/2019/08/msg00010.html
  7. https://seclists.org/bugtraq/2019/Oct/9
  8. https://seclists.org/bugtraq/2019/Sep/35
  9. https://seclists.org/bugtraq/2019/Sep/38
  10. https://security.netapp.com/advisory/ntap-20190822-0003/
  11. https://support.apple.com/kb/HT210634
  12. https://support.apple.com/kb/HT210722
  13. https://usn.ubuntu.com/4097-1/
  14. https://usn.ubuntu.com/4097-2/
  15. https://www.debian.org/security/2019/dsa-4527
  16. https://www.debian.org/security/2019/dsa-4529
  17. https://www.tenable.com/security/tns-2021-14
  18. http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00019.html
  19. http://seclists.org/fulldisclosure/2019/Oct/15
  20. http://seclists.org/fulldisclosure/2019/Oct/55