Korean
<< Back
VID 22915
Severity 30
Port 80, ...
Protocol TCP
Class CGI
Detailed Description According to its banner, the version of PHP running on the remote web server is 7.1.x prior to 7.1.29. It is, therefore, affected by a heap-based buffer over-read condition within _estrndup of the exif_process_IFD_TAG in the exif.c script.
An unauthenticated, remote attacker can exploit this, to cause a denial of service condition or the execution of arbitrary code.

* References:
http://php.net/ChangeLog-7.php#7.1.29

* Platforms Affected:
PHP Prior to 7.1.29
Any operating system Any version
Recommendation Upgrade to the latest version of PHP (7.1.29 or later), available from the PHP web site at http://www.php.net/downloads.php
Related URL CVE-2019-11036 (CVE)
Related URL (SecurityFocus)
Related URL (ISS)