PT-2018-2651 · Php+3 · Php+3

Kaiyi Dot Xu

·

Published

2018-08-03

·

Updated

2020-08-24

·

CVE-2018-14883

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions PHP versions prior to 5.6.37 PHP versions 7.0.x prior to 7.0.31 PHP versions 7.1.x prior to 7.1.20 PHP versions 7.2.x prior to 7.2.8
Description The issue is related to an Integer Overflow that leads to a heap-based buffer over-read in the exif thumbnail extract function of exif.c. This can potentially allow a remote attacker to cause a denial of service.
Recommendations For PHP versions prior to 5.6.37, update to version 5.6.37 or later. For PHP versions 7.0.x prior to 7.0.31, update to version 7.0.31 or later. For PHP versions 7.1.x prior to 7.1.20, update to version 7.1.20 or later. For PHP versions 7.2.x prior to 7.2.8, update to version 7.2.8 or later.

Exploit

Fix

Integer Overflow

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2077
BDU:2019-01269
CVE-2018-14883
DLA-1490-1
DSA-4353-1
MGASA-2018-0390
SUSE-SU-2018:2681-1
USN-3766-1
USN-3766-2

Affected Products

Alt Linux
Php
Suse
Ubuntu