CVE-2016-7128

MEDIUM

Php < 5.6.24 - Information Disclosure

Title source: rule

Description

The exif_process_IFD_in_TIFF function in ext/exif/exif.c in PHP before 5.6.25 and 7.x before 7.0.10 mishandles the case of a thumbnail offset that exceeds the file size, which allows remote attackers to obtain sensitive information from process memory via a crafted TIFF image.

Scores

CVSS v3 5.3
EPSS 0.0219
EPSS Percentile 84.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Classification

CWE
CWE-200
Status published

Affected Products (12)

php/php < 5.6.24
php/php
php/php
php/php
php/php
php/php
php/php
php/php
php/php
php/php
php/php
n/a/n/a

Timeline

Published Sep 12, 2016
Tracked Since Feb 18, 2026