Description
The exif_process_IFD_in_MAKERNOTE function in ext/exif/exif.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (out-of-bounds array access and memory corruption), obtain sensitive information from process memory, or possibly have unspecified other impact via a crafted JPEG image.
Remediation
References
Related Vulnerabilities
Lighttpd Use After Free Vulnerability (CVE-2013-4560)
WordPress Plugin Page Builder by SiteOrigin Cross-Site Request Forgery (2.10.15)
WordPress Plugin Nmedia MailChimp Widget 'abs_path' Parameter Remote File Include (3.1)
MySQL CVE-2019-2914 Vulnerability (CVE-2019-2914)
WordPress Plugin Payment Form for PayPal Pro Multiple Cross-Site Scripting Vulnerabilities (1.0.1)