Assessment
Why it matters
EPSS is 7.6%; technical severity is CVSS 6.5.
When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.
Who should care
- Teams operating Ubuntu Linux, Debian Linux, Fedora +3 more
- Vulnerability and exposure management teams
- Security operations teams monitoring exploitation activity
Response plan
What I would do
- Confirm whether Ubuntu Linux, Debian Linux, Fedora +3 more is present in the environment.
- Identify affected versions and establish whether vulnerable services are exposed or reachable.
- Debian Security advisory Dsa 4626
- Review relevant security telemetry for evidence of attempted or successful exploitation.
- Document the remediation decision and track it to verified completion.
Treatment intelligence
Remediation intelligence
Vendor sources are listed before government and third-party guidance. Confirm product applicability and change prerequisites before deployment.
Technical details
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
- CWE
- CWE-125
- Affected versions
- Canonical Ubuntu Linux (Version 12.04 | Version 14.04 | Version 16.04 | Version 18.04); Debian Debian Linux (Version 8.0 | Version 9.0 | Version 10.0); Fedoraproject Fedora (Version 30 | Version 31); Opensuse Leap (Version 15.1); PHP PHP (Start Including 7.2.0, End Including 7.2.26 | Start Including 7.3.0, End Including 7.3.13 | Version 7.4.0); Tenable Security Center (End Excluding 5.19.0)
- Fixed versions
- Tenable Security Center (Fixed from 5.19.0)
- Published
- 23 December 2019
- Attack vector
- Network
- Privileges required
- None
- User interaction
- None
Signal timeline
- CVE published
- Latest EPSS score: 7.6%
- Signal calculated at 15
External references
- Debian Third-party advisory Msg00034
- Ubuntu Third-party advisory 4239 1
- Lists Opensuse Third-party advisory Msg00036
- Lists Fedoraproject Technical reference N7GCOAE6KVHYJ3UQ4KLPLTGSLX6IRVRN
- Lists Fedoraproject Technical reference XWRQPYXVG43Q7DXMXH6UVWMKWGUW552F
- Seclists Third-party advisory
- Seclists Third-party advisory
- Seclists Third-party advisory
- Security Netapp Third-party advisory Ntap 20200103 0002
- Tenable Third-party advisory Tns 2021 14