CVE-2018-12882
published 2018-06-26CVE-2018-12882: exif_read_from_impl in ext/exif/exif.c in PHP 7.2.x through 7.2.7 allows attackers to trigger a use-after-free (in exif_read_from_file) because it closes a…
PriorityP349critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
6.80%
93.3th percentile
exif_read_from_impl in ext/exif/exif.c in PHP 7.2.x through 7.2.7 allows attackers to trigger a use-after-free (in exif_read_from_file) because it closes a stream that it is not responsible for closing. The vulnerable code is reachable through the PHP exif_read_data function.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| php | php | 7.2.0 – 7.2.7 | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Festo Didactic SE MES PC
cisa_ics·2026-01-27·CVSS 7.5
[HIGH] Festo Didactic SE MES PC
ICS Advisory
##
Festo Didactic SE MES PC
Release DateJanuary 27, 2026
Alert CodeICSA-26-027-02
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## Summary
MES PCs shipped with Windows 10 come pre-installed with XAMPP. XAMPP is a bundle of third-party open-source applications including the Apache HTTP Server, the MariaDB database and more. From time to time, vulnerabilities in these applications are discovered. These are fixed in newer versions of XAMPP by updating the bundled applications. MES PCs shipped with Windows 10 include a copy of XAMPP which contains around 140 such vulnerabilities listed in this advisory. They can be fixed by replacing XAMPP with Festo Didactic's Factory Control Panel application.
The
Ubuntu
PHP vulnerability
vendor_ubuntu·2018-07-05·CVSS 9.8
CVE-2018-12882 [CRITICAL] PHP vulnerability
Title: PHP vulnerability
Summary: PHP could be made to crash or run programs if it opened a specially crafted
file.
USN-3702-1 fixed a vulnerability in PHP. PHP 7.2.7 did not actually include
the fix for CVE-2018-12882. This update adds a backported patch to correct
the issue.
We apologize for the inconvenience.
Original advisory details:
It was discovered that PHP incorrectly handled exif tags in certain images.
A remote attacker could use this issue to cause PHP to crash, resulting in
a denial of service, or possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
PHP vulnerability
vendor_ubuntu·2018-07-04
CVE-2018-12882 PHP vulnerability
Title: PHP vulnerability
Summary: PHP could be made to crash or run programs if it opened a specially crafted
file.
It was discovered that PHP incorrectly handled exif tags in certain images.
A remote attacker could use this issue to cause PHP to crash, resulting in
a denial of service, or possibly execute arbitrary code.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. In general, a standard system update will make all the necessary
changes.
Red Hat
php: Use-after-free reachable via the exif.c:exif_read_from_impl() function
vendor_redhat·2018-06-03·CVSS 9.8
CVE-2018-12882 [CRITICAL] CWE-416 php: Use-after-free reachable via the exif.c:exif_read_from_impl() function
php: Use-after-free reachable via the exif.c:exif_read_from_impl() function
exif_read_from_impl in ext/exif/exif.c in PHP 7.2.x through 7.2.7 allows attackers to trigger a use-after-free (in exif_read_from_file) because it closes a stream that it is not responsible for closing. The vulnerable code is reachable through the PHP exif_read_data function.
Package: php (Red Hat Enterprise Linux 5) - Not affected
Package: php53 (Red Hat Enterprise Linux 5) - Not affected
Package: php (Red Hat Enterprise Linux 6) - Not affected
Package: php (Red Hat Enterprise Linux 7) - Not affected
Package: php (Red Hat Enterprise Linux 8) - Not affected
Package: rh-php70-php (Red Hat Software Collections) - Not affected
Package: rh-php71-php (Red Hat Software Collections) - Not affected
GHSA
GHSA-p666-3cc6-g2c6: exif_read_from_impl in ext/exif/exif
ghsa_unreviewed·2022-05-14
CVE-2018-12882 [CRITICAL] CWE-416 GHSA-p666-3cc6-g2c6: exif_read_from_impl in ext/exif/exif
exif_read_from_impl in ext/exif/exif.c in PHP 7.2.x through 7.2.7 allows attackers to trigger a use-after-free (in exif_read_from_file) because it closes a stream that it is not responsible for closing. The vulnerable code is reachable through the PHP exif_read_data function.
OSV
php7.2 vulnerability
osv·2018-07-05·CVSS 9.8
CVE-2018-12882 [CRITICAL] php7.2 vulnerability
php7.2 vulnerability
USN-3702-1 fixed a vulnerability in PHP. PHP 7.2.7 did not actually include
the fix for CVE-2018-12882. This update adds a backported patch to correct
the issue.
We apologize for the inconvenience.
Original advisory details:
It was discovered that PHP incorrectly handled exif tags in certain images.
A remote attacker could use this issue to cause PHP to crash, resulting in
a denial of service, or possibly execute arbitrary code.
OSV
CVE-2018-12882: exif_read_from_impl in ext/exif/exif
osv·2018-06-25·CVSS 9.8
CVE-2018-12882 [CRITICAL] CVE-2018-12882: exif_read_from_impl in ext/exif/exif
exif_read_from_impl in ext/exif/exif.c in PHP 7.2.x through 7.2.7 allows attackers to trigger a use-after-free (in exif_read_from_file) because it closes a stream that it is not responsible for closing. The vulnerable code is reachable through the PHP exif_read_data function.
No detection rules found.
No public exploits indexed.
HackerOne
CVE-2018-12882: heap-use-after-free in PHP 7.2 through 7.2.6, possible 7.2.7
hackerone·2018-09-01·CVSS 9.8
CVE-2018-12882 [CRITICAL] CVE-2018-12882: heap-use-after-free in PHP 7.2 through 7.2.6, possible 7.2.7
CVE-2018-12882: heap-use-after-free in PHP 7.2 through 7.2.6, possible 7.2.7
`exif_read_data` in PHP 7.2 through 7.2.6 (and possibly 7.2.7) is vulnerable to a heap use after free when fed a specially crafted JPEG. Any online service that uses PHP 7.2 and reads EXIF data from uploaded JPEGs is potentially vulnerable to this flaw.
```
USE_ZEND_ALLOC=0 ./php-e147eb2 -r 'exif_read_data(file_get_contents("/full/path/to/test.jpg"));'
echo "Lw==" | base64 -d > test.jpg
od -tx1 test.jpg
0000000 2f
0000001
```
```
==15865==ERROR: AddressSanitizer: heap-use-after-free on address 0x611000000ad0 at pc 0x0000013d8100 bp 0x7fff9778bda0 sp 0x7fff9778bd98
READ of size 8 at 0x611000000ad0 thread T0
#0 0x13d80ff in _php_stream_free /root/php-7.2.6/main/streams/streams.c:373:13
#1 0xe4a08f in exif_read_
Bugzilla
CVE-2018-12882 php: Use-after-free reachable via the exif.c:exif_read_from_impl() function
bugzilla·2018-06-27·CVSS 9.8
CVE-2018-12882 [CRITICAL] CVE-2018-12882 php: Use-after-free reachable via the exif.c:exif_read_from_impl() function
CVE-2018-12882 php: Use-after-free reachable via the exif.c:exif_read_from_impl() function
PHP versions 7.2.x through 7.2.7 are vulnerable to a heap-use-after-free in streams.c:_php_stream_free() that is reachable via the exif.c:exif_read_from_impl() function. An attacker could exploit this via a crafted file to potentially execute arbitrary code.
The vulnerable PHP exif_read_data() function was modified in version 7.2.0 to support local files and stream resources.
Upstream Bug:
https://bugs.php.net/bug.php?id=76409
Upstream Patch:
http://git.php.net/?p=php-src.git;a=commit;h=3fdde65617e9f954e2c964768aac8831005497e5
Reference:
http://php.net/manual/en/function.exif-read-data.php
Discussion:
Created php tracking bugs for this issue:
Affects: fedora-28 [bug 1595503]
---
This
Bugzilla
CVE-2018-12882 php: Use-after-free reachable via the exif.c:exif_read_from_impl() function [fedora-28]
bugzilla·2018-06-27·CVSS 9.8
CVE-2018-12882 [CRITICAL] CVE-2018-12882 php: Use-after-free reachable via the exif.c:exif_read_from_impl() function [fedora-28]
CVE-2018-12882 php: Use-after-free reachable via the exif.c:exif_read_from_impl() function [fedora-28]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-28.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the followi
http://www.securityfocus.com/bid/104551https://bugs.php.net/bug.php?id=76409https://security.netapp.com/advisory/ntap-20181109-0001/https://usn.ubuntu.com/3702-1/https://usn.ubuntu.com/3702-2/http://www.securityfocus.com/bid/104551https://bugs.php.net/bug.php?id=76409https://security.netapp.com/advisory/ntap-20181109-0001/https://usn.ubuntu.com/3702-1/https://usn.ubuntu.com/3702-2/
2018-06-26
Published