PT-2018-2651 · Php+3 · Php+3

Kaiyi Dot Xu

·

Publicado

2018-08-03

·

Atualizado

2020-08-24

·

CVE-2018-14883

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions PHP versions prior to 5.6.37 PHP versions 7.0.x prior to 7.0.31 PHP versions 7.1.x prior to 7.1.20 PHP versions 7.2.x prior to 7.2.8
Description The issue is related to an Integer Overflow that leads to a heap-based buffer over-read in the exif thumbnail extract function of exif.c. This can potentially allow a remote attacker to cause a denial of service.
Recommendations For PHP versions prior to 5.6.37, update to version 5.6.37 or later. For PHP versions 7.0.x prior to 7.0.31, update to version 7.0.31 or later. For PHP versions 7.1.x prior to 7.1.20, update to version 7.1.20 or later. For PHP versions 7.2.x prior to 7.2.8, update to version 7.2.8 or later.

Exploit

Correção

Integer Overflow

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-2077
BDU:2019-01269
CVE-2018-14883
DLA-1490-1
DSA-4353-1
MGASA-2018-0390
SUSE-SU-2018:2681-1
USN-3766-1
USN-3766-2

Produtos afetados

Alt Linux
Php
Suse
Ubuntu