CVE-2016-10158

Source
https://cve.org/CVERecord?id=CVE-2016-10158
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-10158.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2016-10158
Downstream
DLA (1)
DSA (1)
MGASA (1)
RHSA (1)
SUSE (3)
UBUNTU (1)
Related
Published
2017-01-24T21:59:00Z
Modified
2026-05-17T11:54:24Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

The exif_convert_any_to_int function in ext/exif/exif.c in PHP before 5.6.30, 7.0.x before 7.0.15, and 7.1.x before 7.1.1 allows remote attackers to cause a denial of service (application crash) via crafted EXIF data that triggers an attempt to divide the minimum representable negative integer by -1.

References

Affected packages