Description
An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in exif_process_IFD_in_MAKERNOTE because of mishandling the data_len variable.
Remediation
References
Related Vulnerabilities
Seo Panel Server-Side Request Forgery (SSRF) Vulnerability (CVE-2025-29452)
Oracle Database Server CVE-2007-5504 Vulnerability (CVE-2007-5504)
WordPress Plugin Absolute Privacy 'abpr_authenticateUser()' Security Bypass (2.0.5)
Jboss EAP Improper Restriction of Excessive Authentication Attempts Vulnerability (CVE-2025-23368)