PT-2018-11449 · Php+3 · Php+3

Geeknik

·

Publicado

2018-06-25

·

Atualizado

2024-06-15

·

CVE-2018-12882

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PHP versions 7.2.x through 7.2.7
Description The issue allows attackers to trigger a use-after-free in the exif read from file function because it closes a stream that it is not responsible for closing. This is reachable through the PHP exif read data function.
Recommendations For PHP versions 7.2.x through 7.2.7, consider updating to a version where this issue is resolved, as the current version allows for a use-after-free exploit through the exif read data function. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-2077
CVE-2018-12882
OPENSUSE-SU-2018_1913-1
OPENSUSE-SU-2018_2014-1
OPENSUSE-SU-2018_2694-1
OPENSUSE-SU-2022_4067-1
OPENSUSE-SU-2024:11167-1
OPENSUSE-SU-2024:11169-1
SUSE-SU-2018:1886-1
SUSE-SU-2018:1936-1
SUSE-SU-2018:1936-2
SUSE-SU-2018:2044-1
SUSE-SU-2018:2682-1
SUSE-SU-2018_1886-1
SUSE-SU-2018_1936-1
SUSE-SU-2018_1936-2
SUSE-SU-2022:4067-1
USN-3702-1
USN-3702-2

Produtos afetados

Alt Linux
Php
Suse
Ubuntu