Upstream information
Description
Integer overflow in the exif_process_IFD_TAG function in exif.c in the exif extension in PHP 5.4.0beta2 on 32-bit platforms allows remote attackers to read the contents of arbitrary memory locations or cause a denial of service via a crafted offset_val value in an EXIF header in a JPEG file, a different vulnerability than CVE-2011-0708.NVD CVSS v2 Base Score: 6.4 (AV:N/AC:L/Au:N/C:P/I:N/A:P)
Novell/SUSE information
Novell Bugzilla entries: 733590, 736169, 738221, 741520, 741859, 742273, 742806, 743308, 744966, 746661, 749111 SUSE Security Advisories:- SUSE-SU-2012:0496-1, published Thu, 12 Apr 2012 23:08:15 +0200 (CEST)
- openSUSE-SU-2012:0426-1, published Thu, 29 Mar 2012 15:08:14 +0200 (CEST)
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| SLE 11 SP1 DEBUGINFO |
| Builds SAT Patch Nr: 5964 |
| SUSE Linux Enterprise Software Development Kit 11 SP1 SUSE Linux Enterprise Software Development Kit 11 SP2 |
| Builds SAT Patch Nr: 5964 |
| SUSE Linux Enterprise Software Development Kit 11 SP1 SUSE Linux Enterprise Software Development Kit 11 SP2 |
| Builds SAT Patch Nr: 5964 |
| SUSE Linux Enterprise Server 11 SP1 SUSE Linux Enterprise Server 11 SP1 for VMware SUSE Linux Enterprise Server 11 SP2 |
| Builds SAT Patch Nr: 5964 |
