CVE-2015-0232Untrusted Pointer Dereference in PHP

Severity
6.8MEDIUMNVD
OSV7.5
EPSS
68.3%
top 1.39%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 27
Latest updateMay 14

Description

The exif_process_unicode function in ext/exif/exif.c in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized pointer free and application crash) via crafted EXIF data in a JPEG image.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages3 packages

Ubuntuphp5/php5< 5.5.9+dfsg-1ubuntu4.6
NVDphp/php5.4.36+59

Patches

🔴Vulnerability Details

3
GHSA
GHSA-pprc-9jwm-mwxq: The exif_process_unicode function in ext/exif/exif2022-05-14
OSV
php5 vulnerabilities2015-02-17
OSV
CVE-2015-0232: The exif_process_unicode function in ext/exif/exif2015-01-27

📋Vendor Advisories

3
Ubuntu
PHP vulnerabilities2015-02-17
Red Hat
php: Free called on unitialized pointer in exif.c2015-01-01
Apple
CVE-2015-0232: OS X El Capitan v10.11

🕵️Threat Intelligence

1
Tenable
[R5] Tenable Products Affected by PHP &lt; 5.5.21 / 5.4.37 Vulnerabilities2015-02-03

💬Community

1
Bugzilla
CVE-2015-0232 php: Free called on unitialized pointer in exif.c2015-01-23
CVE-2015-0232 — Untrusted Pointer Dereference in PHP | cvebase