CVE-2004-1065

6 documents6 sources
Severity
10.0CRITICAL
EPSS
7.2%
top 8.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 10
Latest updateApr 29

Description

Buffer overflow in the exif_read_data function in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to execute arbitrary code via a long section name in an image file.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages3 packages

NVDphp/php49 versions+48
NVDopenpkg/openpkg2.1, 2.2, current+2
NVDtrustix/secure_linux2.0, 2.1, 2.2+2

Also affects: Ubuntu Linux 4.1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-vhmx-6whg-m8hv: Buffer overflow in the exif_read_data function in PHP before 42022-04-29
CVEList
CVE-2004-1065: Buffer overflow in the exif_read_data function in PHP before 42004-12-22

📋Vendor Advisories

2
Ubuntu
PHP vulnerabilities2004-12-17
Red Hat
security flaw2004-12-15

💬Community

1
Bugzilla
CVE-2004-1065 security flaw2018-08-16