5.5
CVSSv3

CVE-2018-14851

Published: 02/08/2018 Updated: 19/08/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

exif_process_IFD_in_MAKERNOTE in ext/exif/exif.c in PHP prior to 5.6.37, 7.0.x prior to 7.0.31, 7.1.x prior to 7.1.20, and 7.2.x prior to 7.2.8 allows remote malicious users to cause a denial of service (out-of-bounds read and application crash) via a crafted JPEG file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

php php

canonical ubuntu linux 12.04

canonical ubuntu linux 14.04

canonical ubuntu linux 16.04

canonical ubuntu linux 18.04

debian debian linux 9.0

debian debian linux 8.0

netapp storage automation store -

Vendor Advisories

Synopsis Moderate: rh-php71-php security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An update for rh-php71-php is now available for Red Hat Software CollectionsRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerabilit ...
Several security issues were fixed in PHP ...
Several security issues were fixed in PHP ...
Multiple security issues were found in PHP, a widely-used open source general purpose scripting language: The EXIF module was susceptible to denial of service/information disclosure when parsing malformed images, the Apache module allowed cross-site-scripting via the body of a "Transfer-Encoding: chunked" request and the IMAP extension performed in ...
exif_process_IFD_in_MAKERNOTE in ext/exif/exifc in PHP 72x before 728 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted JPEG file(CVE-2018-14851) exif_read_from_impl in ext/exif/exifc in PHP 72x through 727 allows attackers to trigger a use-after-free (in exif_read_from_file) be ...
exif_process_IFD_in_MAKERNOTE in ext/exif/exifc in PHP before 5637, 70x before 7031, and 71x before 7120, allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted JPEG file(CVE-2018-14851) An issue was discovered in PHP before 5637, 70x before 7031, and 71x before 7120 An I ...
SecurityCenter leverages third-party software to help provide underlying functionality Two separate third-party components (PHP and OpenSSL) were found to contain vulnerabilities, and updated versions have been made available by the providers Out of caution and in line with good practice, Tenable opted to upgrade the bundled libraries to address ...