Description
In PHP versions 7.2.x below 7.2.9, 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while parsing EXIF data with exif_read_data() function, it is possible for malicious data to cause PHP to read one byte of uninitialized memory. This could potentially lead to information disclosure or crash.
Remediation
References
Related Vulnerabilities
Jenkins Improper Input Validation Vulnerability (CVE-2012-6072)
PHP Improper Encoding or Escaping of Output Vulnerability (CVE-2024-5585)
MySQL CVE-2014-2438 Vulnerability (CVE-2014-2438)
WordPress Plugin Generate PDF using Contact Form 7 Cross-Site Scripting (3.5)
WordPress Plugin WP Dynamic Keywords Injector Cross-Site Request Forgery (2.3.15)