CVE-2011-4566
29.11.2011, 00:55
Integer overflow in the exif_process_IFD_TAG function in exif.c in the exif extension in PHP 5.4.0beta2 on 32-bit platforms allows remote attackers to read the contents of arbitrary memory locations or cause a denial of service via a crafted offset_val value in an EXIF header in a JPEG file, a different vulnerability than CVE-2011-0708.Enginsight
Vendor | Product | Version |
---|---|---|
php | php | 5.3.0 ≤ 𝑥 < 5.3.9 |
php | php | 5.4.0:beta2 |
debian | debian_linux | 5.0 |
debian | debian_linux | 6.0 |
debian | debian_linux | 7.0 |
canonical | ubuntu_linux | 8.04 |
canonical | ubuntu_linux | 10.04 |
canonical | ubuntu_linux | 10.10 |
canonical | ubuntu_linux | 11.04 |
canonical | ubuntu_linux | 11.10 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
References