CVE-2014-3670

Priority
Description
The exif_ifd_make_value function in exif.c in the EXIF extension in PHP
before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 operates on
floating-point arrays incorrectly, which allows remote attackers to cause a
denial of service (heap memory corruption and application crash) or
possibly execute arbitrary code via a crafted JPEG image with TIFF
thumbnail data that is improperly handled by the exif_thumbnail function.
Assigned-to
mdeslaur
Notes
Package
Source: php5 (LP Ubuntu Debian)
Upstream:released (5.4.34, 5.5.18, 5.6.1)
Ubuntu 14.04 ESM (Trusty Tahr):released (5.5.9+dfsg-1ubuntu4.5)
Patches:
Upstream:http://git.php.net/?p=php-src.git;a=commit;h=ddb207e7fa2e9adeba021a1303c3781efda5409b (5.5)
Upstream:http://git.php.net/?p=php-src.git;a=commit;h=287c91c1f060dc85a8bdb51488c50db8614448b7 (5.4)
More Information

Updated: 2019-12-05 18:37:34 UTC (commit dd38ff22974aae499eb50644b9d5a2817483cbdb)