CVE-2016-6291: Buffer Overflow
The exifprocessIFDinMAKERNOTE function in ext/exif/exif.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (out-of-bounds array access and memory corruption), obtain sensitive information from process memory, or possibly have unspecified other impact via a crafted JPEG image.
Other sources
Fixed bug (Out of bound read in exifprocessIFDinMAKERNOTE). (CVE-2016-6291)
— PHP
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6291?
CVE-2016-6291 has a medium severity rating as it can lead to denial of service and memory corruption.
How do I fix CVE-2016-6291?
To fix CVE-2016-6291, upgrade PHP to version 5.5.38, 5.6.24, or 7.0.9 or higher.
What type of vulnerability is CVE-2016-6291?
CVE-2016-6291 is a vulnerability that allows remote attackers to exploit out-of-bounds array access and cause memory corruption.
Can CVE-2016-6291 expose sensitive information?
Yes, CVE-2016-6291 can potentially allow attackers to obtain sensitive information from the process memory.
Which PHP versions are affected by CVE-2016-6291?
CVE-2016-6291 affects PHP versions before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9.