Description
Integer overflow in the exif_process_IFD_TAG function in exif.c in PHP before 4.3.11 may allow remote attackers to execute arbitrary code via an IFD tag that leads to a negative byte count.
Remediation
References
Related Vulnerabilities
Moodle CVE-2021-36402 Vulnerability (CVE-2021-36402)
Apache Tomcat Unprotected Transport of Credentials Vulnerability (CVE-2023-28708)
WordPress Plugin Appointment Calendar Multiple Cross-Site Scripting Vulnerabilities (2.7.4)
WordPress Plugin Category Specific RSS feed Subscription Cross-Site Request Forgery (2.0)
WordPress Plugin LearnPress-WordPress LMS SQL Injection (3.2.6.7)