Severity
Medium
Analysis Summary
1) An error within the “exif_process_IFD_in_MAKERNOTE()” function (ext/exif/exif.c) can be exploited to cause an out-of-bounds read memory access.
2) An error within the “exif_iif_add_value()” function (ext/exif/exif.c) can be exploited to cause an out-of-bounds read memory access.
Impact
Denial of Service
Affected Vendors
PHP Group
Affected Products
Remediation
Update to version 7.1.28 or 7.2.17