When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 it is possible to supply it wit…
中危 CVSS 4.8
摘要
When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
受影响产品
- :
- :
- :
- :
数据来源
- NVD DATABASE
原始链接
- http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00036.html Mailing List
- https://bugs.php.net/bug.php?id=78793 Exploit
- https://lists.debian.org/debian-lts-announce/2019/12/msg00034.html Mailing List
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N7GCOAE6KVHYJ3UQ4KLPLTGSLX6IRVRN/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XWRQPYXVG43Q7DXMXH6UVWMKWGUW552F/
- https://seclists.org/bugtraq/2020/Feb/27 Mailing List
- https://seclists.org/bugtraq/2020/Feb/31 Mailing List
- https://seclists.org/bugtraq/2021/Jan/3 Mailing List
- https://security.netapp.com/advisory/ntap-20200103-0002/ Third Party Advisory
- https://usn.ubuntu.com/4239-1/ Third Party Advisory
- https://www.debian.org/security/2020/dsa-4626 Third Party Advisory
- https://www.debian.org/security/2020/dsa-4628 Third Party Advisory
- https://www.tenable.com/security/tns-2021-14 Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00036.html Mailing List
- https://bugs.php.net/bug.php?id=78793 Exploit
- https://lists.debian.org/debian-lts-announce/2019/12/msg00034.html Mailing List
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N7GCOAE6KVHYJ3UQ4KLPLTGSLX6IRVRN/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XWRQPYXVG43Q7DXMXH6UVWMKWGUW552F/
- https://seclists.org/bugtraq/2020/Feb/27 Mailing List
- https://seclists.org/bugtraq/2020/Feb/31 Mailing List
- https://seclists.org/bugtraq/2021/Jan/3 Mailing List
- https://security.netapp.com/advisory/ntap-20200103-0002/ Third Party Advisory
- https://usn.ubuntu.com/4239-1/ Third Party Advisory
- https://www.debian.org/security/2020/dsa-4626 Third Party Advisory
- https://www.debian.org/security/2020/dsa-4628 Third Party Advisory
- https://www.tenable.com/security/tns-2021-14 Third Party Advisory
时间线
- nvd_ingest NVD