Description
The exif_process_IFD_in_JPEG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not validate IFD sizes, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via crafted header data.
Remediation
References
Related Vulnerabilities
MediaWiki Improper Access Control Vulnerability (CVE-2015-8008)
WordPress Plugin Contact Form 7 Database Addon-CFDB7 Unspecified Vulnerability (1.2.5.7)
PHP Other Vulnerability (CVE-2015-2787)
WordPress Plugin Twitter Friends Widget Cross-Site Scripting (3.1)
Joomla Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-9933)