CVE-2004-1065
Vulnerability Summary
Timeline
Description
Buffer overflow in the exif_read_data function in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to execute arbitrary code via a long section name in an image file.
CVSS Metrics
- v2.0•HIGH•Score: 10AV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS Trends
Current EPSS score: 7.16%• Percentile: 92%
Affected Systems
- openpkg•openpkg
2.1 | 2.2 | current
- Unknown•PHP
3.0 | 3.0.1 | 3.0.2 | 3.0.3 | 3.0.4 | 3.0.5 | 3.0.6 | 3.0.7 | 3.0.8 | 3.0.9 | 3.0.10 | 3.0.11 | 3.0.12 | 3.0.13 | 3.0.14 | 3.0.15 | 3.0.16 | 3.0.17 | 3.0.18 | 4.0 | 4.0.1 | 4.0.1:patch1 | 4.0.1:patch2 | 4.0.2 | 4.0.3 | 4.0.3:patch1 | 4.0.4 | 4.0.5 | 4.0.6 | 4.0.7 | 4.0.7:rc1 | 4.0.7:rc2 | 4.0.7:rc3 | 4.1.0 | 4.1.1 | 4.1.2 | 4.2 | 4.2.0 | 4.2.1 | 4.2.2 | 4.2.3 | 4.3.0 | 4.3.1 | 4.3.2 | 4.3.3 | 4.3.4 | 4.3.5 | 4.3.6 | 4.3.7 | 4.3.8 | 4.3.9 | 5.0:rc1 | 5.0:rc2 | 5.0:rc3 | 5.0.0 | 5.0.1 | 5.0.2
- trustix•secure_linux
2.0 | 2.1 | 2.2
- ubuntu•ubuntu_linux
4.1
References (10)
- http://www.redhat.com/support/errata/RHSA-2005-032.html
- http://www.novell.com/linux/security/advisories/2005_02_php4_mod_php4.html
- http://www.php.net/release_4_3_10.php
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10877
- http://www.mandriva.com/security/advisories?name=MDKSA-2004:151
- https://bugzilla.fedora.us/show_bug.cgi?id=2344
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18517
- http://msgs.securepoint.com/cgi-bin/get/bugtraq0412/157.html
- http://www.securityfocus.com/advisories/9028
- http://www.redhat.com/support/errata/RHSA-2004-687.html