Lucene search

K
hackeroneChamalH1:516237
HistoryMar 27, 2019 - 3:18 a.m.

Internet Bug Bounty: Uninitialized read in exif_process_IFD_in_MAKERNOTE

2019-03-2703:18:50
chamal
hackerone.com
23

0.003 Low

EPSS

Percentile

69.1%

This bug is present in exif_process_IFD_in_MAKERNOTE method of ext/exif/exif.c file.

Detailed description and steps to reproduce for this bug is present in bug report submitted to php.net.
Bug Report : https://bugs.php.net/bug.php?id=77563
PHP version : 7.1.26
CVE-ID : 2019-9638

Impact

Uninitialized data may leak data from memory.