PT-2018-11449 · Php+3 · Php+3

Geeknik

·

Published

2018-06-25

·

Updated

2024-06-15

·

CVE-2018-12882

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PHP versions 7.2.x through 7.2.7
Description The issue allows attackers to trigger a use-after-free in the exif read from file function because it closes a stream that it is not responsible for closing. This is reachable through the PHP exif read data function.
Recommendations For PHP versions 7.2.x through 7.2.7, consider updating to a version where this issue is resolved, as the current version allows for a use-after-free exploit through the exif read data function. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2077
CVE-2018-12882
OPENSUSE-SU-2018_1913-1
OPENSUSE-SU-2018_2014-1
OPENSUSE-SU-2018_2694-1
OPENSUSE-SU-2022_4067-1
OPENSUSE-SU-2024:11167-1
OPENSUSE-SU-2024:11169-1
SUSE-SU-2018:1886-1
SUSE-SU-2018:1936-1
SUSE-SU-2018:1936-2
SUSE-SU-2018:2044-1
SUSE-SU-2018:2682-1
SUSE-SU-2018_1886-1
SUSE-SU-2018_1936-1
SUSE-SU-2018_1936-2
SUSE-SU-2022:4067-1
USN-3702-1
USN-3702-2

Affected Products

Alt Linux
Php
Suse
Ubuntu