RULE(RULE ID:305674)

Rule General Information
Release Date: 2012-11-28
Rule Name: WEB-OTHER PHP Exif Header Parsing Integer Overflow Vulnerability -3 (CVE-2011-4566)
Severity:
CVE ID:
Rule Protection Details
Description: Integer overflow in the exif_process_IFD_TAG function in exif.c in the exif extension in PHP 5.4.0beta2 on 32-bit platforms allows remote attackers to read the contents of arbitrary memory locations or cause a denial of service via a crafted offset_val value in an EXIF header in a JPEG file.
Impact: An attacker can exploit the affected software with a integer overflow vulnerability. Successful exploit leads to execute arbitrary code, and failed exploit may disturb the software logic and cause denial of service.
Affected OS: Windows, Other Unix, FreeBSD, Linux
Reference: SecurityFocusBID:50907
Solutions
More advisories have been published on the website, please visit for more suggestions:
http://www.php.net/archive/2012.php#id2012-01-11-1