CVE-2011-4566

Modified
Published: 29 Nov 2011, 00:00
Last modified:07 Aug 2024, 00:09

Vulnerability Summary

Overall Risk (default)
medium
43/100
CVSS Score
6.4 MEDIUM
v2.0 (nvd)
EPSS Score
36.44% HIGH
36% probability -7.16%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

29 Nov 2011, 00:00
Published
Vulnerability first disclosed
07 Aug 2024, 00:09
Last Modified
Vulnerability information updated

Description

Integer overflow in the exif_process_IFD_TAG function in exif.c in the exif extension in PHP 5.4.0beta2 on 32-bit platforms allows remote attackers to read the contents of arbitrary memory locations or cause a denial of service via a crafted offset_val value in an EXIF header in a JPEG file, a different vulnerability than CVE-2011-0708.

CVSS Metrics

  • v2.0MEDIUMScore: 6.4AV:N/AC:L/Au:N/C:P/I:N/A:P

EPSS Trends

Current EPSS score: 36.44% Percentile: 97%

Techniques & Countermeasures

  • CWE-189Numeric Errors

    Weaknesses in this category are related to improper calculation or conversion of numbers.

Affected Systems

  • canonicalubuntu_linux

    8.04 | 10.04 | 10.10 | 11.04 | 11.10

  • debiandebian_linux

    5.0 | 6.0 | 7.0

  • UnknownPHP

    ≥ 5.3.0, < 5.3.9 | 5.4.0:beta2

References (13)