VYPR
Unrated severityNVD Advisory· Published Aug 5, 2009· Updated Jun 16, 2026

CVE-2009-2687

CVE-2009-2687

Description

The exif_read_data function in the Exif module in PHP before 5.2.10 allows remote attackers to cause a denial of service (crash) via a malformed JPEG image with invalid offset fields, a different issue than CVE-2005-3353.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • PHP/PHP2 versions
    cpe:2.3:a:php:php:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:php:php:*:*:*:*:*:*:*:*range: <5.2.10
    • (no CPE)range: <5.2.10
  • Debian/linux3 versions
    cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*
    • cpe:2.3:o:debian:debian_linux:5.0:*:*:*:*:*:*:*
    • cpe:2.3:o:debian:debian_linux:6.0:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

18

News mentions

0

No linked articles in our index yet.