Comment 1Huzaifa S. Sidhpurwala
2016-10-20 05:54:42 UTC
Analysis:
Flaw is a result of a lack of validation when offset data is used from a TIFF image to read from the input stream. This may result in a OOB read. You need an attacker controlled malicious tiff image, which needs to be processed by exif_read_data() to trigger this flaw.
This issue has been addressed in the following products:
Red Hat Software Collections for Red Hat Enterprise Linux 6
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS
Red Hat Software Collections for Red Hat Enterprise Linux 7
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS
Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS
Via RHSA-2016:2750 https://rhn.redhat.com/errata/RHSA-2016-2750.html