Security Advisory

CVE-2019-9639

7.5
HIGH

Vulnerability Description

An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in exif_process_IFD_in_MAKERNOTE because of mishandling the data_len variable.
Published Date March 9, 2019
Official Source NIST NVD Advisory