PT-2019-5435 · Php+7 · Php+7

Published

2019-03-08

·

Updated

2022-04-05

·

CVE-2019-9639

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions PHP versions prior to 7.1.27 PHP versions 7.2.x prior to 7.2.16 PHP versions 7.3.x prior to 7.3.3
Description The issue is related to an uninitialized read in the exif process IFD in MAKERNOTE function of the EXIF component due to mishandling of the data len variable. This can lead to a buffer overflow, potentially allowing a remote attacker to gain unauthorized access to protected information.
Recommendations For PHP versions prior to 7.1.27, update to version 7.1.27 or later. For PHP versions 7.2.x prior to 7.2.16, update to version 7.2.16 or later. For PHP versions 7.3.x prior to 7.3.3, update to version 7.3.3 or later.

Exploit

Fix

Buffer Overflow

Use of Uninitialized Resource

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2020:1624
ALT-PU-2019-1396
BDU:2020-03142
CESA-2020_1624
CVE-2019-9639
DLA-1741-1
DSA-4403-1
OPENSUSE-SU-2019:1572-1
OPENSUSE-SU-2019:1573-1
OPENSUSE-SU-2019_1293-1
OPENSUSE-SU-2019_1503-1
OPENSUSE-SU-2019_1572-1
OPENSUSE-SU-2019_1573-1
RHSA-2019:2519
RHSA-2019:3299
RHSA-2020:1624
RHSA-2020_1624
RLSA-2020:1624
SUSE-SU-2019:0988-1
SUSE-SU-2019:1325-1
SUSE-SU-2019:14013-1
SUSE-SU-2019:1461-1
SUSE-SU-2019_14013-1
SUSE-SU-2019_1461-1
USN-3922-1
USN-3922-2
USN-3922-3

Affected Products

Alt Linux
Almalinux
Centos
Php
Red Hat
Rocky Linux
Suse
Ubuntu