DescriptionDhananjay Arunesh
2020-04-03 12:45:57 UTC
A vulnerability was found in PHP versions 7.2.x below 7.2.9, 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while parsing EXIF data with exif_read_data() function, it is possible for malicious data to cause PHP to read one byte of uninitialized memory. This could potentially lead to information disclosure or crash.
Comment 1Dhananjay Arunesh
2020-04-03 12:46:26 UTC
Created php tracking bugs for this issue:
Affects: fedora-all [bug 1820602]
Comment 2Dhananjay Arunesh
2020-04-03 12:46:49 UTC
This issue has been addressed in the following products:
Red Hat Software Collections for Red Hat Enterprise Linux 7
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
Via RHSA-2020:5275 https://access.redhat.com/errata/RHSA-2020:5275