First published: Thu Mar 07 2019(Updated: )
An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in exif_process_IFD_in_TIFF.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PHP PHP | <7.1.27 | |
PHP PHP | >=7.2.0<7.2.16 | |
PHP PHP | >=7.3.0<7.3.3 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 | |
Canonical Ubuntu Linux | =12.04 | |
Canonical Ubuntu Linux | =14.04 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =18.04 | |
Canonical Ubuntu Linux | =18.10 | |
openSUSE Leap | =15.0 | |
openSUSE Leap | =15.1 | |
openSUSE Leap | =42.3 | |
Netapp Storage Automation Store | ||
PHP PHP | <7.1.27 | 7.1.27 |
debian/php5 | ||
debian/php7.0 | ||
debian/php7.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-9641 is a vulnerability in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3, which allows for uninitialized read in exif_process_IFD_in_TIFF.
CVE-2019-9641 is considered critical with a severity rating of 9.8 out of 10.
The affected software includes PHP versions before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3.
To fix CVE-2019-9641, you should update your PHP installation to version 7.1.27 or higher, 7.2.16 or higher, or 7.3.3 or higher.
You can find more information about CVE-2019-9641 at the following references: [ChangeLog-7.php](https://www.php.net/ChangeLog-7.php#7.1.27), [opensuse-security-announce](http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00083.html), [opensuse-security-announce](http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00104.html).