CVE-2016-6291 PUBLISHED

The exif_process_IFD_in_MAKERNOTE function in ext/exif/exif.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (out-of-bounds array access and memory corruption), obtain sensitive information from process memory, or possibly have unspecified other impact via a crafted JPEG image.

EPSS 6.55% · 91.1th percentile

Risk Scores

EPSS Score
6.55%
91.1th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSphp7.00, 7.0.1-5, 7.0.2-1
Ubuntu:14.04:LTSphp5*, 5.5.9+dfsg-1ubuntu4.12, 5.5.9+dfsg-1ubuntu4.14

Timeline

References

Open in Interactive Console →