Description
exif_read_from_impl in ext/exif/exif.c in PHP 7.2.x through 7.2.7 allows attackers to trigger a use-after-free (in exif_read_from_file) because it closes a stream that it is not responsible for closing. The vulnerable code is reachable through the PHP exif_read_data function.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-4835 | exif_read_from_impl in ext/exif/exif.c in PHP 7.2.x through 7.2.7 allows attackers to trigger a use-after-free (in exif_read_from_file) because it closes a stream that it is not responsible for closing. The vulnerable code is reachable through the PHP exif_read_data function. |
Ubuntu USN |
USN-3702-1 | PHP vulnerability |
Ubuntu USN |
USN-3702-2 | PHP vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T08:45:02.487Z
Reserved: 2018-06-25T00:00:00.000Z
Link: CVE-2018-12882
No data.
Status : Modified
Published: 2018-06-26T03:29:00.210
Modified: 2024-11-21T03:46:02.080
Link: CVE-2018-12882
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Ubuntu USN