Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2005-0525

The php_next_marker function in image.c for PHP 4.2.2, 4.3.9, 4.3.10 and 5.0.3, as reachable by the getimagesize PHP function, allows remote attackers to cause a denial of service (infinite loop) via a JPEG image with an invalid marker value, which causes a negative length value to be passed to php_stream_seek.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.079
EPSS Ranking 91.6%
CVSS Severity
CVSS v2 Score 5.0
References
Products affected by CVE-2005-0525
  • Php » Php » Version: 4.2.2
    cpe:2.3:a:php:php:4.2.2
  • Php » Php » Version: 4.3.10
    cpe:2.3:a:php:php:4.3.10
  • Php » Php » Version: 4.3.9
    cpe:2.3:a:php:php:4.3.9
  • Php » Php » Version: 5.0.3
    cpe:2.3:a:php:php:5.0.3


Contact Us

Shodan ® - All rights reserved