CVE-2011-4566
published 2011-11-29CVE-2011-4566: Integer overflow in the exif_process_IFD_TAG function in exif.c in the exif extension in PHP 5.4.0beta2 on 32-bit platforms allows remote attackers to read the…
PriorityP333medium6.4CVSS 2.0
AVNACLAuNCPINAP
EPSS
6.56%
93.0th percentile
Integer overflow in the exif_process_IFD_TAG function in exif.c in the exif extension in PHP 5.4.0beta2 on 32-bit platforms allows remote attackers to read the contents of arbitrary memory locations or cause a denial of service via a crafted offset_val value in an EXIF header in a JPEG file, a different vulnerability than CVE-2011-0708.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| php | php | — | — |
| php | php | >= 5.3.0 < 5.3.9 | 5.3.9 |
CVSS provenance
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:P
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
PHP vulnerability
vendor_ubuntu·2011-12-14
CVE-2011-4566 PHP vulnerability
Title: PHP vulnerability
Summary: PHP could be made to crash or disclose sensitive information if it
processed a specially crafted image file.
Florent Hochwelker discovered that PHP incorrectly handled certain EXIF
headers in JPEG files. A remote attacker could exploit this issue to
view sensitive information or cause the PHP server to crash.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
php: integer overflow in exif_process_IFD_TAG() may lead to DoS or arbitrary memory disclosure
vendor_redhat·2011-10-27·CVSS 4.3
CVE-2011-4566 [MEDIUM] CWE-190 php: integer overflow in exif_process_IFD_TAG() may lead to DoS or arbitrary memory disclosure
php: integer overflow in exif_process_IFD_TAG() may lead to DoS or arbitrary memory disclosure
Integer overflow in the exif_process_IFD_TAG function in exif.c in the exif extension in PHP 5.4.0beta2 on 32-bit platforms allows remote attackers to read the contents of arbitrary memory locations or cause a denial of service via a crafted offset_val value in an EXIF header in a JPEG file, a different vulnerability than CVE-2011-0708.
GHSA
GHSA-hp65-4pq5-qqw7: Integer overflow in the exif_process_IFD_TAG function in exif
ghsa_unreviewed·2022-05-17·CVSS 4.3
CVE-2011-4566 [MEDIUM] GHSA-hp65-4pq5-qqw7: Integer overflow in the exif_process_IFD_TAG function in exif
Integer overflow in the exif_process_IFD_TAG function in exif.c in the exif extension in PHP 5.4.0beta2 on 32-bit platforms allows remote attackers to read the contents of arbitrary memory locations or cause a denial of service via a crafted offset_val value in an EXIF header in a JPEG file, a different vulnerability than CVE-2011-0708.
No detection rules found.
Tenable
Tenable Network Security Podcast 110
blogs_tenable·2012-01-24
Tenable Network Security Podcast 110
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bugzilla
CVE-2011-4566 php: integer overflow in exif_process_IFD_TAG() may lead to DoS or arbitrary memory disclosure
bugzilla·2011-11-29·CVSS 4.3
CVE-2011-4566 [MEDIUM] CVE-2011-4566 php: integer overflow in exif_process_IFD_TAG() may lead to DoS or arbitrary memory disclosure
CVE-2011-4566 php: integer overflow in exif_process_IFD_TAG() may lead to DoS or arbitrary memory disclosure
Common Vulnerabilities and Exposures assigned an identifier CVE-2011-4566 to
the following vulnerability:
Name: CVE-2011-4566
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4566
Assigned: 20111128
Reference: https://bugs.php.net/bug.php?id=60150
Integer overflow in the exif_process_IFD_TAG function in exif.c in the
exif extension in PHP 5.4.0beta2 on 32-bit platforms allows remote
attackers to read the contents of arbitrary memory locations or cause
a denial of service via a crafted offset_val value in an EXIF header
in a JPEG file, a different vulnerability than CVE-2011-0708.
Although the CVE description specifically indicates 5.4.0beta2 is affected, it does look
http://lists.apple.com/archives/security-announce/2012/May/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-03/msg00016.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0071.htmlhttp://secunia.com/advisories/47253http://secunia.com/advisories/48668http://support.apple.com/kb/HT5281http://www.debian.org/security/2012/dsa-2399http://www.mandriva.com/security/advisories?name=MDVSA-2011:197http://www.redhat.com/support/errata/RHSA-2012-0019.htmlhttp://www.securityfocus.com/bid/50907https://bugs.php.net/bug.php?id=60150https://exchange.xforce.ibmcloud.com/vulnerabilities/71612https://www.ubuntu.com/usn/USN-1307-1/http://lists.apple.com/archives/security-announce/2012/May/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-03/msg00016.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0071.htmlhttp://secunia.com/advisories/47253http://secunia.com/advisories/48668http://support.apple.com/kb/HT5281http://www.debian.org/security/2012/dsa-2399http://www.mandriva.com/security/advisories?name=MDVSA-2011:197http://www.redhat.com/support/errata/RHSA-2012-0019.htmlhttp://www.securityfocus.com/bid/50907https://bugs.php.net/bug.php?id=60150https://exchange.xforce.ibmcloud.com/vulnerabilities/71612https://www.ubuntu.com/usn/USN-1307-1/
2011-11-29
Published