CVE-2016-10158
24.01.2017, 21:59
The exif_convert_any_to_int function in ext/exif/exif.c in PHP before 5.6.30, 7.0.x before 7.0.15, and 7.1.x before 7.1.1 allows remote attackers to cause a denial of service (application crash) via crafted EXIF data that triggers an attempt to divide the minimum representable negative integer by -1.Enginsight
| Vendor | Product | Version |
|---|---|---|
| php | php | 𝑥 ≤ 5.6.29 |
| php | php | 7.0.0 |
| php | php | 7.0.1 |
| php | php | 7.0.2 |
| php | php | 7.0.3 |
| php | php | 7.0.4 |
| php | php | 7.0.5 |
| php | php | 7.0.6 |
| php | php | 7.0.7 |
| php | php | 7.0.8 |
| php | php | 7.0.9 |
| php | php | 7.0.10 |
| php | php | 7.0.11 |
| php | php | 7.0.12 |
| php | php | 7.0.13 |
| php | php | 7.0.14 |
| php | php | 7.1.0 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Common Weakness Enumeration
References