Description
The exif_process_IFD_in_MAKERNOTE function in ext/exif/exif.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (out-of-bounds array access and memory corruption), obtain sensitive information from process memory, or possibly have unspecified other impact via a crafted JPEG image.
Remediation
References
Related Vulnerabilities
WordPress Plugin Orbit Fox by ThemeIsle Multiple Vulnerabilities (2.10.2)
WordPress Plugin WP AutoComplete Search SQL Injection (1.0.4)
WordPress Plugin User Role by BestWebSoft Cross-Site Scripting (1.5.1)
IBM WebSEAL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2018-1805)