Description
When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.31, 7.2.x below 7.2.21 and 7.3.x below 7.3.8 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1878-1 | php5 security update |
Debian DSA |
DSA-4527-1 | php7.3 security update |
Debian DSA |
DSA-4529-1 | php7.0 security update |
EUVD |
EUVD-2019-2749 | When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.31, 7.2.x below 7.2.21 and 7.3.x below 7.3.8 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash. |
Ubuntu USN |
USN-4097-1 | PHP vulnerabilities |
Ubuntu USN |
USN-4097-2 | PHP vulnerabilities |
References
History
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Subscriptions
Apple
Subscribe
Mac Os X
Subscribe
Canonical
Subscribe
Ubuntu Linux
Subscribe
Debian
Subscribe
Debian Linux
Subscribe
Opensuse
Subscribe
Leap
Subscribe
Php
Subscribe
Php
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Rhel Software Collections
Subscribe
Software Collections
Subscribe
Tenable
Subscribe
Tenable.sc
Subscribe
Status: PUBLISHED
Assigner: php
Published:
Updated: 2024-09-16T19:31:07.181Z
Reserved: 2019-04-09T00:00:00.000Z
Link: CVE-2019-11041
No data.
Status : Modified
Published: 2019-08-09T20:15:11.050
Modified: 2024-11-21T04:20:25.723
Link: CVE-2019-11041
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN