CVE-2005-1043

7 documents6 sources
Severity
5.0MEDIUM
EPSS
1.1%
top 21.87%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 14
Latest updateMay 1

Description

exif.c in PHP before 4.3.11 allows remote attackers to cause a denial of service (memory consumption and crash) via an EXIF header with a large IFD nesting level, which causes significant stack recursion.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages7 packages

NVDphp/php11 versions+10
NVDsgi/propack3.0
NVDapple/mac_os_x10.3.9, 10.4, 10.4.1+2
NVDconectiva/linux10.0, 9.0+1
NVDsuse/suse_linux28 versions+27

Patches

🔴Vulnerability Details

2
GHSA
GHSA-q2c2-w3x6-jhjj: exif2022-05-01
CVEList
CVE-2005-1043: exif2005-04-12

📋Vendor Advisories

2
Ubuntu
PHP4 vulnerabilities2005-04-14
Red Hat
security flaw2005-03-31

💬Community

1
Bugzilla
CVE-2005-1043 security flaw2018-08-16