mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-31 05:59:31 +02:00
18 lines
818 B
Markdown
18 lines
818 B
Markdown
### [CVE-2020-7064](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-7064)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
In PHP versions 7.2.x below 7.2.9, 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while parsing EXIF data with exif_read_data() function, it is possible for malicious data to cause PHP to read one byte of uninitialized memory. This could potentially lead to information disclosure or crash.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- https://www.oracle.com/security-alerts/cpujan2021.html
|
|
|
|
#### Github
|
|
- https://github.com/Live-Hack-CVE/CVE-2020-7064
|
|
|