VDB
CVE-2005-1042
CVE-2005-1042
PUBLISHED
CVSS 7.5 HIGH
Integer overflow in the exif_process_IFD_TAG function in exif.c in PHP before 4.3.11 may allow remote attackers to execute arbitrary code via an IFD tag that leads to a negative byte count.
EPSS 4.02% · 89.6th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
4.02%
89.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | * |
| php | php | 4.3.1, 4.3.2, 4.3.5 |
Timeline
- Apr 12, 2005 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
- Oct 31, 2023 EPSS Score
- Dec 22, 2023 EPSS Score
References
- MDKSA-2005:072 vendor-advisory
- GLSA-200504-15 vendor-advisory
- APPLE-SA-2005-06-08 vendor-advisory
- https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=154021 url
- oval:org.mitre.oval:def:10822 vdb
- USN-112-1 vendor-advisory
- http://cvs.php.net/diff.php/php-src/ext/exif/exif.c?r1=1.118.2.33&r2=1.118.2.34&ty=u patch
- http://www.redhat.com/support/errata/RHSA-2005-405.html technical
- http://www.redhat.com/support/errata/RHSA-2005-406.html technical
- https://nvd.nist.gov/vuln/detail/CVE-2005-1042 advisory
- https://usn.ubuntu.com/112-1 url