7.5
CVSSv2

CVE-2019-9641

Published: 09/03/2019 Updated: 05/04/2022
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An issue exists in the EXIF component in PHP prior to 7.1.27, 7.2.x prior to 7.2.16, and 7.3.x prior to 7.3.3. There is an uninitialized read in exif_process_IFD_in_TIFF.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

php php

debian debian linux 9.0

debian debian linux 8.0

canonical ubuntu linux 12.04

canonical ubuntu linux 14.04

canonical ubuntu linux 16.04

canonical ubuntu linux 18.04

canonical ubuntu linux 18.10

opensuse leap 15.0

opensuse leap 15.1

opensuse leap 42.3

netapp storage automation store -

Vendor Advisories

Several security issues were fixed in PHP ...
Several security issues were fixed in PHP ...
Several security issues were fixed in PHP ...

Github Repositories

PHP 5.6.40-r7 with some patches for Rocky Linux 8 compatibility and OpenSSL 1.1 / TLS v1.3 support

The PHP Interpreter This is archived version of PHP5 Fixed up to CVE-2019-9641 (03/08/2019) Guidelines for contributors CODING_STANDARDS READMEGIT-RULES READMEMAILINGLIST_RULES READMERELEASE_PROCESS