SB2018072419 - Memory corruption in php5 (Alpine package)
Published: July 24, 2018
Security Bulletin ID
SB2018072419
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Denial of service
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Memory corruption (CVE-ID: CVE-2018-14883)
The vulnerability allows a remote attacker to cause DoS condition on the target system.The weakness exists due to integer overflow when processing exif_read_data in any 32-bit system. A remote attacker can trigger heap-based buffer overflow in exif_thumbnail_extract of exif.c and cause the service to crash.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=195c4dea4525cc85ef4ab449d2c739b6b5081b48
- https://git.alpinelinux.org/aports/commit/?id=4a7ccf578f5caf82b4c9120ac266ff49f245549a
- https://git.alpinelinux.org/aports/commit/?id=7a2897f5fb53f23d6d00a7b63c4a7a2771887bb7
- https://git.alpinelinux.org/aports/commit/?id=8bb30c7afcb27955fa636ba010e2c13b641488fa
- https://git.alpinelinux.org/aports/commit/?id=bf663ad1c43b55eb0775d0f653fbecc9e0c4bb47
- https://git.alpinelinux.org/aports/commit/?id=ca40e97beb964bebd52acde85a91194a444e4d9c
- https://git.alpinelinux.org/aports/commit/?id=f21552df8b35137d4fe31dbd14c342d797a69319
- https://git.alpinelinux.org/aports/commit/?id=3d5ecd32fb9f5fd0c0c79faea57624bb2c26fb83
- https://git.alpinelinux.org/aports/commit/?id=d42b915a2245405763bb485ededfbdb01393f109