ZeroHour

CVE-2019-9639

PoC
CVSS 3.1
7.5 high
EPSS
8%p95
Published
()
Modified
Description

An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in exif_process_IFD_in_MAKERNOTE because of mishandling the data_len variable.

Vendors
phpdebiancanonicalopensusenetappredhat
Products
php, debian linux, ubuntu linux, leap, storage automation store, software collections
Weakness
CWE-908, CWE-909
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.