Description
When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.29, 7.2.x below 7.2.18 and 7.3.x below 7.3.5 can be caused to read past allocated buffer in exif_process_IFD_TAG function. This may lead to information disclosure or crash.
Remediation
References
Related Vulnerabilities
Apache HTTP Server Other Vulnerability (CVE-2007-1742)
WordPress 4.6.x Prototype Pollution (4.6 - 4.6.22)
Artifactory Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-10321)
WordPress Plugin WP-RecentComments Information Disclosure (2.2.7)
Dotclear Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2014-1613)