CVE-2009-2687

The exif_read_data function in the Exif module in PHP before 5.2.10 allows remote attackers to cause a denial of service (crash) via a malformed JPEG image with invalid offset fields, a different issue than CVE-2005-3353.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 92%
VendorProductVersion
phpphp
𝑥
< 5.2.10
debiandebian_linux
4.0
debiandebian_linux
5.0
debiandebian_linux
6.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
php4
karmic
dne
jaunty
dne
intrepid
dne
hardy
dne
dapper
ignored
php5
karmic
not-affected
jaunty
Fixed 5.2.6.dfsg.1-3ubuntu4.2
released
intrepid
Fixed 5.2.6-2ubuntu4.3
released
hardy
Fixed 5.2.4-2ubuntu5.7
released
dapper
Fixed 5.1.2-1ubuntu3.15
released
References