Attack (Attack ID:324647)

Release Date2016/08/22

Attack NameWEB PHP exif_process_user_comment Null Pointer Dereference (CVE-2016-6292)

Severity

BUG ID

CVE ID

 

Description

A denial of service vulnerability exists in the Exif module of PHP due to a null pointer dereference in exif_process_user_comment.
Impact:Remote code execution
Affected System:Windows, Linux, FreeBSD, Other Unix
Additional References:CVE-2016-6292

 

Solution

Update vendor's patch.