The exif_convert_any_to_int function in ext/exif/exif.c in PHP before 5.6.30, 7.0.x before 7.0.15, and 7.1.x before 7.1.1 allows remote attackers to cause a denial of service (application crash) via crafted EXIF data that triggers an attempt to divide the minimum representable negative integer by -1.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Php | Php | * | 5.6.29 (including) |
Php | Php | 7.0.0 (including) | 7.0.0 (including) |
Php | Php | 7.0.1 (including) | 7.0.1 (including) |
Php | Php | 7.0.2 (including) | 7.0.2 (including) |
Php | Php | 7.0.3 (including) | 7.0.3 (including) |
Php | Php | 7.0.4 (including) | 7.0.4 (including) |
Php | Php | 7.0.5 (including) | 7.0.5 (including) |
Php | Php | 7.0.6 (including) | 7.0.6 (including) |
Php | Php | 7.0.7 (including) | 7.0.7 (including) |
Php | Php | 7.0.8 (including) | 7.0.8 (including) |
Php | Php | 7.0.9 (including) | 7.0.9 (including) |
Php | Php | 7.0.10 (including) | 7.0.10 (including) |
Php | Php | 7.0.11 (including) | 7.0.11 (including) |
Php | Php | 7.0.12 (including) | 7.0.12 (including) |
Php | Php | 7.0.13 (including) | 7.0.13 (including) |
Php | Php | 7.0.14 (including) | 7.0.14 (including) |
Php | Php | 7.1.0 (including) | 7.1.0 (including) |