PT-2016-2080 · Php+2 · Php+2

Hanno Böck

·

Publicado

2016-05-06

·

Atualizado

2022-07-20

·

CVE-2016-4544

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PHP versions prior to 5.5.35 PHP versions 5.6.x prior to 5.6.21 PHP versions 7.x prior to 7.0.6
Description The issue is caused by a buffer overflow in the exif process TIFF in JPEG function. This can be exploited by a remote attacker using specially crafted header data, potentially leading to a denial of service or other unspecified impacts, such as out-of-bounds memory reading.
Recommendations For PHP versions prior to 5.5.35, update to version 5.5.35 or later. For PHP versions 5.6.x prior to 5.6.21, update to version 5.6.21 or later. For PHP versions 7.x prior to 7.0.6, update to version 7.0.6 or later. As a temporary workaround, consider disabling the exif process TIFF in JPEG function until a patch is available.

Exploit

Correção

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2016-01432
CVE-2016-4544
DLA-499-1
DSA-3602-1
RHSA-2016:2750
SUSE-SU-2016:1504-1
SUSE-SU-2016:1581-1
SUSE-SU-2016:1638-1
USN-2984-1

Produtos afetados

Php
Suse
Ubuntu