CVE Tools

Description

The exif_process_IFD_in_JPEG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not validate IFD sizes, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via crafted header data.

In plain language

AI Worth attention

If you run PHP and your website/server handles uploaded or processed JPEG images (with EXIF/metadata), an attacker may be able to crash PHP using a specially crafted photo; a typical small business should update PHP to the fixed versions.

Executive summary

In PHP (CVE-2016-4543), the exif_process_IFD_in_JPEG code path does not properly validate EXIF Image File Directory (IFD) sizes, so a remote attacker sending crafted JPEG metadata can trigger a denial of service (out-of-bounds read) when PHP processes EXIF data.

If affected, business impact
Website or API outageService crashes during uploadsOperational disruptionPotential data processing instability

What to do now

  1. Check your PHP version (from your server’s “phpinfo” page, command line output, or your hosting control panel) and confirm whether you use PHP’s EXIF/JPEG handling features.
  2. Identify whether your business accepts or processes JPEG uploads or remote images (for example, profile photos, document scans, or image previews that extract EXIF metadata).
  3. Plan an upgrade of PHP to one of the fixed versions: 5.5.35 or newer, 5.6.21 or newer, or 7.0.6 or newer.
  4. Deploy the PHP upgrade to production and verify normal image upload/processing behavior.
  5. If you cannot upgrade right away, restrict who can upload/trigger image processing and add upload size/type limits to reduce the chance of crafted JPEGs being processed.
Patch / advisory Some work to apply

CVSS Vector Breakdown

AV:NAC:LPR:NUI:NS:UC:HI:HA:H
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:NPrivileges Required
None
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

hp
commercial·USaka hpe, hewlett packard
php
oss-project·USaka php language, pear, pecl
fedoraproject
oss-project·USaka fedora project
PHP Group
oss-projectaka pear, php
PHPLibraryLibrary
OSS Libraries
and 1 more affected products View all →

Exploitability

Official Patch Available

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

2 techniques
Initial Access
Privilege Escalation
View detailed technique mapping

References

and 16 more references View all →

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2016-4543 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store