CVE-2019-9638: High severity PHP PHP vulnerability
An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in exifprocessIFDinMAKERNOTE because of mishandling the makernote->offset relationship to valuelen.
Other sources
Fixed bug (Uninitialized read in exifprocessIFDinMAKERNOTE). (CVE-2019-9638)
— PHP
Affected Software
Remediation
Patch Available
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2019-9638?
CVE-2019-9638 is a vulnerability in the EXIF component of PHP that allows uninitialized read in exif_process_IFD_in_MAKERNOTE.
What is the severity of CVE-2019-9638?
The severity of CVE-2019-9638 is high with a CVSS score of 7.5.
Which versions of PHP are affected by CVE-2019-9638?
Versions before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3 are affected by CVE-2019-9638.
How can the uninitialized read vulnerability in exif_process_IFD_in_MAKERNOTE be exploited?
The uninitialized read vulnerability in exif_process_IFD_in_MAKERNOTE can be exploited by manipulating EXIF data in an image file.
Is there a patch available for CVE-2019-9638?
Yes, patches are available for PHP versions 7.1.27, 7.2.16, and 7.3.3 to address CVE-2019-9638.