exif.c in PHP before 4.3.11 allows remote attackers to cause a denial of service (memory consumption and crash) via an EXIF header with a large IFD nesting level, which causes significant stack recursion.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Php | Php | 4.3.0 (including) | 4.3.0 (including) |
Php | Php | 4.3.1 (including) | 4.3.1 (including) |
Php | Php | 4.3.2 (including) | 4.3.2 (including) |
Php | Php | 4.3.3 (including) | 4.3.3 (including) |
Php | Php | 4.3.4 (including) | 4.3.4 (including) |
Php | Php | 4.3.5 (including) | 4.3.5 (including) |
Php | Php | 4.3.6 (including) | 4.3.6 (including) |
Php | Php | 4.3.7 (including) | 4.3.7 (including) |
Php | Php | 4.3.8 (including) | 4.3.8 (including) |
Php | Php | 4.3.9 (including) | 4.3.9 (including) |
Php | Php | 4.3.10 (including) | 4.3.10 (including) |
Propack | Sgi | 3.0 (including) | 3.0 (including) |
Linux | Conectiva | 9.0 (including) | 9.0 (including) |
Linux | Conectiva | 10.0 (including) | 10.0 (including) |
Red Hat Enterprise Linux 3 | RedHat | php-0:4.3.2-23.ent | * |
Red Hat Enterprise Linux 4 | RedHat | php-0:4.3.9-3.6 | * |
Php4 | Ubuntu | dapper | * |
Php4 | Ubuntu | edgy | * |
Php5 | Ubuntu | dapper | * |
Php5 | Ubuntu | devel | * |
Php5 | Ubuntu | edgy | * |
Php5 | Ubuntu | feisty | * |