6.8
CVSSv2

CVE-2015-0232

Published: 27/01/2015 Updated: 07/11/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The exif_process_unicode function in ext/exif/exif.c in PHP prior to 5.4.37, 5.5.x prior to 5.5.21, and 5.6.x prior to 5.6.5 allows remote malicious users to execute arbitrary code or cause a denial of service (uninitialized pointer free and application crash) via crafted EXIF data in a JPEG image.

Vulnerable Product Search on Vulmon Subscribe to Product

php php 5.6.1

php php 5.5.0

php php 5.6.0

php php 5.4.12

php php 5.5.19

php php 5.4.15

php php 5.5.16

php php 5.4.19

php php 5.5.1

php php 5.5.5

php php 5.4.34

php php 5.6.4

php php 5.5.17

php php 5.4.14

php php 5.4.8

php php 5.5.14

php php 5.4.17

php php 5.5.7

php php 5.6.2

php php 5.4.35

php php 5.4.22

php php 5.4.9

php php 5.4.11

php php 5.5.12

php php 5.4.10

php php 5.5.6

php php 5.4.2

php php 5.5.3

php php 5.4.27

php php 5.5.8

php php 5.4.16

php php 5.4.28

php php 5.4.21

php php 5.4.5

php php 5.4.26

php php 5.5.15

php php 5.5.11

php php 5.5.13

php php 5.5.4

php php 5.4.24

php php 5.4.23

php php 5.4.6

php php 5.4.30

php php 5.4.13

php php 5.4.29

php php 5.4.0

php php 5.4.3

php php 5.4.18

php php 5.5.10

php php 5.6.3

php php 5.4.1

php php 5.5.18

php php 5.4.20

php php 5.4.25

php php 5.4.7

php php 5.5.20

php php 5.4.4

php php 5.5.2

php php

php php 5.5.9

Vendor Advisories

Several security issues were fixed in PHP ...
sapi/cgi/cgi_mainc in the CGI component in PHP through 5436, 55x through 5520, and 56x through 564, when mmap is used to read a php file, does not properly consider the mapping's length during processing of an invalid file that begins with a # character and lacks a newline character, which causes an out-of-bounds read and might (1) allo ...
sapi/cgi/cgi_mainc in the CGI component in PHP through 5436, 55x through 5520, and 56x through 564, when mmap is used to read a php file, does not properly consider the mapping's length during processing of an invalid file that begins with a # character and lacks a newline character, which causes an out-of-bounds read and might (1) allo ...
An uninitialized pointer use flaw was found in PHP's Exif extension A specially crafted JPEG or TIFF file could cause a PHP application using the exif_read_data() function to crash or, possibly, execute arbitrary code with the privileges of the user running that PHP application ...
PHP contains a use-after-free error in the process_nested_data() function in ext/standard/var_unserializerre With specially crafted input passed to the unserialize() method, a remote attacker can dereference already freed memory and potentially execute arbitrary code (CVE-2014-8142 / CVE-2015-0231) PHP contains a flaw in the exif_process_unicod ...