CVE-2018-14883
published 2018-08-03CVE-2018-14883: An issue was discovered in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and 7.2.x before 7.2.8. An Integer Overflow leads to a heap-based…
PriorityP343high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
8.97%
94.7th percentile
An issue was discovered in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and 7.2.x before 7.2.8. An Integer Overflow leads to a heap-based buffer over-read in exif_thumbnail_extract of exif.c.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| php | php | < 5.6.37 | 5.6.37 |
| php | php | >= 7.0.0 < 7.0.31 | 7.0.31 |
| php | php | >= 7.1.0 < 7.1.20 | 7.1.20 |
| php | php | >= 7.2.0 < 7.2.8 | 7.2.8 |
| php5 | php5 | >= 0 < 5.6.37-r0 | 5.6.37-r0 |
| php5 | php5 | >= 0 < 5.5.9+dfsg-1ubuntu4.26 | 5.5.9+dfsg-1ubuntu4.26 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Festo Didactic SE MES PC
cisa_ics·2026-01-27·CVSS 7.5
[HIGH] Festo Didactic SE MES PC
ICS Advisory
##
Festo Didactic SE MES PC
Release DateJanuary 27, 2026
Alert CodeICSA-26-027-02
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## Summary
MES PCs shipped with Windows 10 come pre-installed with XAMPP. XAMPP is a bundle of third-party open-source applications including the Apache HTTP Server, the MariaDB database and more. From time to time, vulnerabilities in these applications are discovered. These are fixed in newer versions of XAMPP by updating the bundled applications. MES PCs shipped with Windows 10 include a copy of XAMPP which contains around 140 such vulnerabilities listed in this advisory. They can be fixed by replacing XAMPP with Festo Didactic's Factory Control Panel application.
The
Ubuntu
PHP vulnerabilities
vendor_ubuntu·2018-09-19·CVSS 5.5
CVE-2018-14851 [MEDIUM] PHP vulnerabilities
Title: PHP vulnerabilities
Summary: Several security issues were fixed in PHP.
USN-3766-1 fixed a vulnerability in PHP. This update provides
the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
It was discovered that PHP incorrectly handled certain exif tags in JPEG
images. A remote attacker could possibly use this issue to cause PHP to
crash, resulting in a denial of service. (CVE-2018-14851, CVE-2018-14883)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
PHP vulnerabilities
vendor_ubuntu·2018-09-18·CVSS 6.5
CVE-2015-9253 [MEDIUM] PHP vulnerabilities
Title: PHP vulnerabilities
Summary: Several security issues were fixed in PHP.
It was discovered that PHP incorrectly handled restarting certain child
processes when php-fpm is used. A remote attacker could possibly use this
issue to cause a denial of service. This issue was only addressed in Ubuntu
18.04 LTS. (CVE-2015-9253)
It was discovered that PHP incorrectly handled certain exif tags in JPEG
images. A remote attacker could possibly use this issue to cause PHP to
crash, resulting in a denial of service. (CVE-2018-14851, CVE-2018-14883)
Instructions: In Ubuntu 16.04 LTS and Ubuntu 18.04 LTS, this update uses a new upstream
release, which includes additional bug fixes.
In general, a standard system update will make all the necessary changes.
Red Hat
php: exif: integer overflow leading to out-of-bound buffer read in exif_thumbnail_extract()
vendor_redhat·2018-06-07·CVSS 7.5
CVE-2018-14883 [HIGH] CWE-190 php: exif: integer overflow leading to out-of-bound buffer read in exif_thumbnail_extract()
php: exif: integer overflow leading to out-of-bound buffer read in exif_thumbnail_extract()
An issue was discovered in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and 7.2.x before 7.2.8. An Integer Overflow leads to a heap-based buffer over-read in exif_thumbnail_extract of exif.c.
Package: php (Red Hat Enterprise Linux 5) - Will not fix
Package: php53 (Red Hat Enterprise Linux 5) - Will not fix
Package: php (Red Hat Enterprise Linux 6) - Will not fix
Package: php (Red Hat Enterprise Linux 7) - Not affected
Package: php (Red Hat Enterprise Linux 8) - Not affected
Package: rh-php70-php (Red Hat Software Collections) - Not affected
Package: rh-php71-php (Red Hat Software Collections) - Not affected
Package: rh-php72-php (Red Hat Software Collections) - Not affected
GHSA
GHSA-42jg-f4qq-3gvm: An issue was discovered in PHP before 5
ghsa_unreviewed·2022-05-13
CVE-2018-14883 [HIGH] CWE-125 GHSA-42jg-f4qq-3gvm: An issue was discovered in PHP before 5
An issue was discovered in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and 7.2.x before 7.2.8. An Integer Overflow leads to a heap-based buffer over-read in exif_thumbnail_extract of exif.c.
OSV
php5, php7.0, php7.2 vulnerabilities
osv·2018-09-18·CVSS 6.5
CVE-2015-9253 [MEDIUM] php5, php7.0, php7.2 vulnerabilities
php5, php7.0, php7.2 vulnerabilities
It was discovered that PHP incorrectly handled restarting certain child
processes when php-fpm is used. A remote attacker could possibly use this
issue to cause a denial of service. This issue was only addressed in Ubuntu
18.04 LTS. (CVE-2015-9253)
It was discovered that PHP incorrectly handled certain exif tags in JPEG
images. A remote attacker could possibly use this issue to cause PHP to
crash, resulting in a denial of service. (CVE-2018-14851, CVE-2018-14883)
OSV
CVE-2018-14883: An issue was discovered in PHP before 5
osv·2018-08-03·CVSS 7.5
CVE-2018-14883 [HIGH] CVE-2018-14883: An issue was discovered in PHP before 5
An issue was discovered in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and 7.2.x before 7.2.8. An Integer Overflow leads to a heap-based buffer over-read in exif_thumbnail_extract of exif.c.
No detection rules found.
No public exploits indexed.
arXiv
Beyond Tag Collision: Cluster-based Memory Management for Tag-based Sanitizers
arxiv_fulltext·2025-09-11
Beyond Tag Collision: Cluster-based Memory Management for Tag-based Sanitizers
Beyond Tag Collision: Cluster-based Memory Management for Tag-based Sanitizers
Mengfei XieThis paper has been accepted to the 2025 ACM SIGSAC Conference on Computer and Communications Security (CCS'25).
Wuhan University
School of Cyber Science and Engineering
[email protected]
Yan Lin
Jianming Fu and Yan Lin are corresponding authors
Jinan University
College of Cyber Security
[email protected]
Hongtao Wu
Wuhan University
School of Cyber Science and Engineering
[email protected]
Jianming Fu
[email protected]
Wuhan University
School of Cyber Science and Engineering
[1]
Chenke Luo
Tulane University
Department of Computer Science
[email protected]
Guojun Peng
Wuhan University
School of Cyber Science and Engineering
[email protected]
Mengfei Xie et al.
## Abstract
Tag-ba
arXiv
PACSan: Enforcing Memory Safety Based on ARM PA
arxiv_fulltext·2022-02-08
PACSan: Enforcing Memory Safety Based on ARM PA
: Enforcing Memory Safety Based on ARM PA
Yuan Li
Tsinghua University
Wende Tan
Tsinghua University
Zhizheng Lv
Tsinghua University
Songtao Yang
Tsinghua University
Mathias Payer
EPFL
Ying Liu
Tsinghua University
Chao Zhang
Tsinghua University
empty
## Abstract
Memory safety is a key security property that stops memory corruption vulnerabilities.
Existing sanitizers enforce checks and catch such bugs during development and testing.
However, they either provide partial memory safety or have overwhelmingly high performance overheads.
Our novel sanitizer enforces spatial and temporal memory safety with no false positives at low performance overheads.
removes the majority of the overheads involved in pointer tracking by
sealing metadata in pointers through ARM PA (Pointer Aut
Bugzilla
CVE-2018-14883 php: exif: integer overflow leading to out-of-bound buffer read in exif_thumbnail_extract()
bugzilla·2018-07-30·CVSS 7.5
CVE-2018-14883 [HIGH] CVE-2018-14883 php: exif: integer overflow leading to out-of-bound buffer read in exif_thumbnail_extract()
CVE-2018-14883 php: exif: integer overflow leading to out-of-bound buffer read in exif_thumbnail_extract()
PHP before versions 5.6.37, 7.0.31, 7.1.20 and 7.2.8 is vulnerable to an integer overflow with subsequent heap-based buffer overflow in the exif.c:exif_thumbnail_extract() function. An attacker could exploit this to cause a denial of service via crafted file.
Upstream Bug:
https://bugs.php.net/bug.php?id=76423
Upstream Patch:
http://git.php.net/?p=php-src.git;a=commit;h=1baeae42703f9b2ec21fff787146eeca08d45535
Discussion:
Created php tracking bugs for this issue:
Affects: fedora-all [bug 1609638]
---
As noted in comment 0, there is an integer overflow in the exif_thumbnail_extract() function, that leads to an out-of-bounds buffer read. This may possibly lead to crash or li
http://php.net/ChangeLog-5.phphttp://php.net/ChangeLog-7.phphttp://www.securityfocus.com/bid/104871https://bugs.php.net/bug.php?id=76423https://lists.debian.org/debian-lts-announce/2018/09/msg00000.htmlhttps://security.netapp.com/advisory/ntap-20181107-0003/https://usn.ubuntu.com/3766-1/https://usn.ubuntu.com/3766-2/https://www.debian.org/security/2018/dsa-4353https://www.tenable.com/security/tns-2018-12http://php.net/ChangeLog-5.phphttp://php.net/ChangeLog-7.phphttp://www.securityfocus.com/bid/104871https://bugs.php.net/bug.php?id=76423https://lists.debian.org/debian-lts-announce/2018/09/msg00000.htmlhttps://security.netapp.com/advisory/ntap-20181107-0003/https://usn.ubuntu.com/3766-1/https://usn.ubuntu.com/3766-2/https://www.debian.org/security/2018/dsa-4353https://www.tenable.com/security/tns-2018-12
2018-08-03
Published