CVE-2018-14883: Integer Overflow
An issue was discovered in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and 7.2.x before 7.2.8. An Integer Overflow leads to a heap-based buffer over-read in exifthumbnailextract of exif.c.
Other sources
Fixed bug (Int Overflow lead to Heap OverFlow in exifthumbnailextract of exif.c). (CVE-2018-14883)
— PHP
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
PHPto a version that resolves this vulnerability.Fixed in 7.0.31 - Upgrade
Upgrade
PHPto a version that resolves this vulnerability.Fixed in 5.6.37 - Upgrade
Upgrade
PHPto a version that resolves this vulnerability.Fixed in 7.1.20 - Upgrade
Upgrade
PHPto a version that resolves this vulnerability.Fixed in 7.2.8
Event History
Frequently Asked Questions
What is the vulnerability ID of this bug?
The vulnerability ID of this bug is CVE-2018-14883.
What is the severity level of CVE-2018-14883?
CVE-2018-14883 has a severity level of high (7.5).
What is the description of CVE-2018-14883?
CVE-2018-14883 is an Integer Overflow vulnerability that leads to a heap-based buffer over-read in exif_thumbnail_extract of exif.c in PHP before version 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and 7.2.x before 7.2.8.
Which software versions are affected by CVE-2018-14883?
CVE-2018-14883 affects PHP versions before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and 7.2.x before 7.2.8.
Where can I find more information about CVE-2018-14883?
You can find more information about CVE-2018-14883 at the following references: CVE Mitre - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-14883, PHP ChangeLog (5.x) - http://php.net/ChangeLog-5.php, PHP ChangeLog (7.x) - http://php.net/ChangeLog-7.php.