CVE-2016-4543

Description

The exif_process_IFD_in_JPEG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not validate IFD sizes, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via crafted header data.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
5.437

Associated Vulnerability

VulnerabilityOS Platform
Update HP System Management Homepage Detection (x64) 7.5.5.6 to latest versionWindows
Update HP System Management Homepage Detection 7.5.5.6 to latest versionWindows
Update HP System Management Homepage Detection 7.5.5.6 to latest version (For Ubuntu)Linux
Update HP System Management Homepage Detection 7.5.5.6 to latest version (For Debian)Linux
Update HP System Management Homepage Detection 7.5.5.6 to latest version (For Centos)Linux
Update HP System Management Homepage Detection 7.5.5.6 to latest version (For RedHat)Linux
Update HP System Management Homepage Detection 7.5.5.6 to latest version (For Suse)Linux
Multiple Vulnerabilities affected in system_management_homepage 3.0.2.77-bNCM
Multiple Vulnerabilities affected in system_management_homepage 3.0.2.77NCM
Multiple Vulnerabilities affected in system_management_homepage 3.0.2-77NCM
Multiple Vulnerabilities affected in system_management_homepage 3.0.2NCM
Multiple Vulnerabilities affected in system_management_homepage 3.0.1.73NCM
Multiple Vulnerabilities affected in system_management_homepage 3.0.1-73NCM
Multiple Vulnerabilities affected in system_management_homepage 3.0.1NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.4NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.3.132NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.1NCM
Multiple Vulnerabilities affected in system_management_homepage 7.4.0NCM
Multiple Vulnerabilities affected in system_management_homepage 6.2.2.7NCM
Multiple Vulnerabilities affected in system_management_homepage 6.1NCM
Multiple Vulnerabilities affected in system_management_homepage 6.0NCM
Multiple Vulnerabilities affected in system_management_homepage 3.2.7NCM
Multiple Vulnerabilities affected in system_management_homepage 3.2.2NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.9NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.8NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.7-168NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.7NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.6-156NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.6NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.5-146NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.5NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.3NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.2-127NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.2NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.0-118NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.0-109NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.0-103(a)NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.0-103NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1NCM
Multiple Vulnerabilities affected in system_management_homepage 2.0.2NCM
Multiple Vulnerabilities affected in system_management_homepage 2.0.1NCM
Multiple Vulnerabilities affected in system_management_homepage 2.0.0NCM
Multiple Vulnerabilities affected in system_management_homepage 7.5.3.1NCM
Multiple Vulnerabilities affected in system_management_homepage 6.2.0NCM
Multiple Vulnerabilities affected in system_management_homepage 6.1.0.102NCM
Multiple Vulnerabilities affected in system_management_homepage 6.1.0-103NCM
Multiple Vulnerabilities affected in system_management_homepage 6.0.0.96NCM
Multiple Vulnerabilities affected in system_management_homepage 6.0.0-95NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.12-200NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.12-118NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.11-197NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.11NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.10-186NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.9-178NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.8-177NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.7.168NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.6.156NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.5.146-bNCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.5.146NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.4.143NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.4-143NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.2.127NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.0.121NCM
Multiple Vulnerabilities affected in system_management_homepage 2.0.2.106NCM
Multiple Vulnerabilities affected in system_management_homepage 2.0.1.104NCM
Multiple Vulnerabilities affected in system_management_homepage 7.2.1NCM
Multiple Vulnerabilities affected in system_management_homepage 7.2NCM
Multiple Vulnerabilities affected in system_management_homepage 2.2.6NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.11.197-aNCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.10.186-cNCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.10.186-bNCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.10.186NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.10NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.8.179NCM
Multiple Vulnerabilities affected in system_management_homepage 7.1NCM
Multiple Vulnerabilities affected in system_management_homepage 7.0NCM
Multiple Vulnerabilities affected in system_management_homepage 6.3.1NCM
Multiple Vulnerabilities affected in system_management_homepage 6.3.0NCM
Multiple Vulnerabilities affected in system_management_homepage 2.2.8NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.15.210NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.15-210NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.15NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.14.20NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.14NCM
Multiple Vulnerabilities affected in system_management_homepage 2.1.12.201NCM
Multiple Vulnerabilities affected in system_management_homepage 7.5.4.3NCM
Multiple Vulnerabilities affected in system_management_homepage 3.0.0.64NCM
Multiple Vulnerabilities affected in system_management_homepage 3.0.0-68NCM
Multiple Vulnerabilities affected in system_management_homepage 3.0.0NCM
Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2016-4543)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234