ZeroHour

CVE-2019-9638

PoC
CVSS 3.1
7.5 high
EPSS
7%p93
Published
()
Modified
Description

An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in exif_process_IFD_in_MAKERNOTE because of mishandling the maker_note->offset relationship to value_len.

Vendors
phpdebiancanonicalopensusenetappredhat
Products
php, debian linux, ubuntu linux, leap, storage automation store, software collections
Weakness
CWE-125
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.