CVE-2019-9641: Critical severity PHP PHP vulnerability
An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in exifprocessIFDinTIFF.
Other sources
Fixed bug (Uninitialized read in exifprocessIFDinTIFF). (CVE-2019-9641)
— PHP
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-9641?
CVE-2019-9641 is a vulnerability in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3, which allows for uninitialized read in exif_process_IFD_in_TIFF.
How severe is CVE-2019-9641?
CVE-2019-9641 is considered critical with a severity rating of 9.8 out of 10.
What is the affected software for CVE-2019-9641?
The affected software includes PHP versions before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3.
How can I fix CVE-2019-9641?
To fix CVE-2019-9641, you should update your PHP installation to version 7.1.27 or higher, 7.2.16 or higher, or 7.3.3 or higher.
Where can I find more information about CVE-2019-9641?
You can find more information about CVE-2019-9641 at the following references: [ChangeLog-7.php](https://www.php.net/ChangeLog-7.php#7.1.27), [opensuse-security-announce](http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00083.html), [opensuse-security-announce](http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00104.html).