Uninitialized read in exif_process_IFD_in_TIFF
Critical
Vulnerability Details
This bug can be reproduced only in 32 bit PHP builds.
This bug is present in exif_process_IFD_in_TIFF method of ext/exif/exif.c file.
Detailed description and steps to reproduce for this bug is present in bug report submitted to php.net.
Bug Report : https://bugs.php.net/bug.php?id=77509
PHP version : 7.1.26
CVE-ID : 2019-9641
## Impact
Uninitialized variables may leak data from memory.
Actions
View on HackerOneReport Stats
- Report ID: 510336
- State: Closed
- Substate: resolved