Impact: Moderate Public Date: 2019-02-23 CWE: CWE-665 Bugzilla: 1688934: CVE-2019-9639 php: Uninitialized read in exif_process_IFD_in_MAKERNOTE An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in exif_process_IFD_in_MAKERNOTE because of mishandling the data_len variable.
The MITRE CVE dictionary describes this issue as:
Find out more about CVE-2019-9639 from the MITRE CVE dictionary dictionary and NIST NVD.
NOTE: The following CVSS v3 metrics and score provided are preliminary and subject to review.
CVSS3 Base Score | 5.3 |
---|---|
CVSS3 Base Metrics | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Attack Vector | Network |
Attack Complexity | Low |
Privileges Required | None |
User Interaction | None |
Scope | Unchanged |
Confidentiality | None |
Integrity Impact | None |
Availability Impact | Low |
Platform | Package | State |
---|---|---|
Red Hat Software Collections for Red Hat Enterprise Linux | rh-php70-php | Under investigation |
Red Hat Software Collections for Red Hat Enterprise Linux | rh-php72-php | Under investigation |
Red Hat Software Collections for Red Hat Enterprise Linux | rh-php71-php | Under investigation |
Red Hat OpenShift Enterprise 3 | rh-php71-php | Under investigation |
Red Hat OpenShift Enterprise 3 | php | Under investigation |
Red Hat OpenShift Enterprise 3 | php55-php | Under investigation |
Red Hat Enterprise Linux 7 | php | Under investigation |
Red Hat Enterprise Linux 6 | php | Under investigation |
Red Hat Enterprise Linux 5 | php53 | Under investigation |
Red Hat Enterprise Linux 5 | php | Under investigation |