CVE-2009-2687
published 2009-08-05CVE-2009-2687: The exif_read_data function in the Exif module in PHP before 5.2.10 allows remote attackers to cause a denial of service (crash) via a malformed JPEG image…
PriorityP420medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
4.38%
90.2th percentile
The exif_read_data function in the Exif module in PHP before 5.2.10 allows remote attackers to cause a denial of service (crash) via a malformed JPEG image with invalid offset fields, a different issue than CVE-2005-3353.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| php | php | < 5.2.10 | 5.2.10 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
PHP vulnerability
vendor_ubuntu·2009-08-24
CVE-2009-2687 PHP vulnerability
Title: PHP vulnerability
Summary: PHP vulnerability
It was discovered that PHP did not properly handle certain malformed
JPEG images when being parsed by the Exif module. A remote attacker could
exploit this flaw and cause the PHP server to crash, resulting in a denial
of service.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Red Hat
php: exif_read_data crash on corrupted JPEG files
vendor_redhat·2009-06-18·CVSS 5.0
CVE-2009-2687 [MEDIUM] php: exif_read_data crash on corrupted JPEG files
php: exif_read_data crash on corrupted JPEG files
The exif_read_data function in the Exif module in PHP before 5.2.10 allows remote attackers to cause a denial of service (crash) via a malformed JPEG image with invalid offset fields, a different issue than CVE-2005-3353.
GHSA
GHSA-gjvv-qp9c-jcr8: The exif_read_data function in the Exif module in PHP before 5
ghsa_unreviewed·2022-05-02·CVSS 5.0
CVE-2009-2687 [MEDIUM] CWE-20 GHSA-gjvv-qp9c-jcr8: The exif_read_data function in the Exif module in PHP before 5
The exif_read_data function in the Exif module in PHP before 5.2.10 allows remote attackers to cause a denial of service (crash) via a malformed JPEG image with invalid offset fields, a different issue than CVE-2005-3353.
No detection rules found.
No public exploits indexed.
http://bugs.php.net/bug.php?id=48378http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00004.htmlhttp://marc.info/?l=bugtraq&m=127680701405735&w=2http://osvdb.org/55222http://secunia.com/advisories/35441http://secunia.com/advisories/36462http://secunia.com/advisories/37482http://secunia.com/advisories/40262http://www.debian.org/security/2009/dsa-1940http://www.mandriva.com/security/advisories?name=MDVSA-2009:145http://www.mandriva.com/security/advisories?name=MDVSA-2009:167http://www.php.net/releases/5_2_10.phphttp://www.securityfocus.com/bid/35440http://www.vupen.com/english/advisories/2009/1632https://exchange.xforce.ibmcloud.com/vulnerabilities/51253https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10695https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6655https://usn.ubuntu.com/824-1/http://bugs.php.net/bug.php?id=48378http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00004.htmlhttp://marc.info/?l=bugtraq&m=127680701405735&w=2http://osvdb.org/55222http://secunia.com/advisories/35441http://secunia.com/advisories/36462http://secunia.com/advisories/37482http://secunia.com/advisories/40262http://www.debian.org/security/2009/dsa-1940http://www.mandriva.com/security/advisories?name=MDVSA-2009:145http://www.mandriva.com/security/advisories?name=MDVSA-2009:167http://www.php.net/releases/5_2_10.phphttp://www.securityfocus.com/bid/35440http://www.vupen.com/english/advisories/2009/1632https://exchange.xforce.ibmcloud.com/vulnerabilities/51253https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10695https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6655https://usn.ubuntu.com/824-1/
2009-08-05
Published