VDB
CVE-2005-1043
CVE-2005-1043
PUBLISHED
CVSS 5 MEDIUM
exif.c in PHP before 4.3.11 allows remote attackers to cause a denial of service (memory consumption and crash) via an EXIF header with a large IFD nesting level, which causes significant stack recursion.
EPSS 1.93% · 78.0th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
1.93%
78.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| sgi | propack | 3.0 |
| suse | suse_linux | 7.3, 7.2, 7.2 |
| conectiva | linux | 10.0, 9.0 |
| apple | mac_os_x | 10.4.1, 10.4, 10.3.9 |
| php | php | 4.3.5, 4.3.7, 4.3.9 |
| n/a | n/a | n/a |
| peachtree | peachtree_linux | release_1 |
| apple | mac_os_x_server | 10.4, 10.4.1, 10.3.9 |
Timeline
- Apr 12, 2005 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 3, 2023 EPSS Score
- Feb 9, 2023 EPSS Score
- Feb 13, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
References
- https://usn.ubuntu.com/112-1 url
- MDKSA-2005:072 vendor-advisory
- APPLE-SA-2005-06-08 vendor-advisory
- oval:org.mitre.oval:def:10307 vdb
- GLSA-200504-15 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2005-1043 advisory
- https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=154025 url
- https://usn.ubuntu.com/112-1/ technical
- http://cvs.php.net/diff.php/php-src/ext/exif/exif.c?r1=1.118.2.29&r2=1.118.2.30&ty=u advisory
- http://www.redhat.com/support/errata/RHSA-2005-406.html patch