VDB
CVE-2005-0525
CVE-2005-0525
PUBLISHED
Reported by mitre · Published April 3, 2005
The php_next_marker function in image.c for PHP 4.2.2, 4.3.9, 4.3.10 and 5.0.3, as reachable by the getimagesize PHP function, allows remote attackers to cause a denial of service (infinite loop) via a JPEG image with an invalid marker value, which causes a negative length value to be passed to php_stream_seek.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| n/a | n/a | n/a, *, * |
Timeline
- Apr 3, 2005 CVE Published
- Feb 4, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
- Dec 22, 2023 EPSS Score
- Feb 13, 2024 EPSS Score
References
- DSA-729 vendor-advisoryx_refsource_DEBIAN
- 1013619 vdb-entryx_refsource_SECTRACK
- RHSA-2005:406 vendor-advisoryx_refsource_REDHAT
- MDKSA-2005:072 vendor-advisoryx_refsource_MANDRAKE
- 15184 vdb-entryx_refsource_OSVDB
- GLSA-200504-15 vendor-advisoryx_refsource_GENTOO
- APPLE-SA-2005-06-08 vendor-advisoryx_refsource_APPLE
- 14792 third-party-advisoryx_refsource_SECUNIA
- ADV-2005-0305 vdb-entryx_refsource_VUPEN
- DSA-708 vendor-advisoryx_refsource_DEBIAN
- 20050331 PHP getimagesize() Multiple Denial of Service Vulnerabilities third-party-advisoryx_refsource_IDEFENSE
- oval:org.mitre.oval:def:11703 vdb-entrysignaturex_refsource_OVAL
- RHSA-2005:405 vendor-advisoryx_refsource_REDHAT