Description
Integer overflow in the exif_process_IFD_TAG function in exif.c in PHP before 4.3.11 may allow remote attackers to execute arbitrary code via an IFD tag that leads to a negative byte count.
Remediation
References
Related Vulnerabilities
WordPress Plugin Advanced XML Reader XML External Entity Information Disclosure (0.3.4)
SharePoint Deserialization of Untrusted Data Vulnerability (CVE-2024-38094)
WordPress Plugin Titan Framework Cross-Site Scripting (1.7.5)
MySQL CVE-2021-35637 Vulnerability (CVE-2021-35637)
Oracle HTTP Server Out-of-bounds Read Vulnerability (CVE-2021-35940)