Описание
The exif_process_IFD_in_TIFF function in ext/exif/exif.c in PHP before 5.6.25 and 7.x before 7.0.10 mishandles the case of a thumbnail offset that exceeds the file size, which allows remote attackers to obtain sensitive information from process memory via a crafted TIFF image.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз | 
|---|---|---|---|---|
| Red Hat Enterprise Linux 5 | php | Will not fix | ||
| Red Hat Enterprise Linux 5 | php53 | Will not fix | ||
| Red Hat Enterprise Linux 6 | php | Will not fix | ||
| Red Hat Enterprise Linux 7 | php | Will not fix | ||
| Red Hat Software Collections | php54-php | Will not fix | ||
| Red Hat Software Collections | php55-php | Will not fix | ||
| Red Hat Software Collections for Red Hat Enterprise Linux 6 | rh-php56 | Fixed | RHSA-2016:2750 | 15.11.2016 | 
| Red Hat Software Collections for Red Hat Enterprise Linux 6 | rh-php56-php | Fixed | RHSA-2016:2750 | 15.11.2016 | 
| Red Hat Software Collections for Red Hat Enterprise Linux 6 | rh-php56-php-pear | Fixed | RHSA-2016:2750 | 15.11.2016 | 
| Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS | rh-php56 | Fixed | RHSA-2016:2750 | 15.11.2016 | 
Показывать по
Дополнительная информация
Статус:
EPSS
5.3 Medium
CVSS3
4.3 Medium
CVSS2
Связанные уязвимости
The exif_process_IFD_in_TIFF function in ext/exif/exif.c in PHP before 5.6.25 and 7.x before 7.0.10 mishandles the case of a thumbnail offset that exceeds the file size, which allows remote attackers to obtain sensitive information from process memory via a crafted TIFF image.
The exif_process_IFD_in_TIFF function in ext/exif/exif.c in PHP before 5.6.25 and 7.x before 7.0.10 mishandles the case of a thumbnail offset that exceeds the file size, which allows remote attackers to obtain sensitive information from process memory via a crafted TIFF image.
The exif_process_IFD_in_TIFF function in ext/exif/exif.c in PHP before ...
The exif_process_IFD_in_TIFF function in ext/exif/exif.c in PHP before 5.6.25 and 7.x before 7.0.10 mishandles the case of a thumbnail offset that exceeds the file size, which allows remote attackers to obtain sensitive information from process memory via a crafted TIFF image.
Уязвимость функции exif_process_ifd_in_tiff интерпретатора языка программирования PHP, позволяющая нарушителю раскрыть защищаемую информацию
EPSS
5.3 Medium
CVSS3
4.3 Medium
CVSS2