CVE-2005-0525
Last modified
CVE-2005-0525 is a vulnerability of currently unknown severity. The php_next_marker function in image.c for PHP 4.2.2, 4.3.9, 4.3.10 and 5.0.3, as reachable by the getimagesize PHP function, allows remote attackers to cause a denial of service (infinite loop) via a JPEG image with an invalid marker value, which causes a negative length value to be passed to php_stream_seek.. EPSS estimates a 2.81% chance of exploitation in the next 30 days.
Description
The php_next_marker function in image.c for PHP 4.2.2, 4.3.9, 4.3.10 and 5.0.3, as reachable by the getimagesize PHP function, allows remote attackers to cause a denial of service (infinite loop) via a JPEG image with an invalid marker value, which causes a negative length value to be passed to php_stream_seek.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Php | Php | 4.2.2 |
| Php | Php | 4.3.9 |
| Php | Php | 4.3.10 |
| Php | Php | 5.0.3 |
References
- http://www.securityfocus.com/archive/1/394797Exploit, Vendor Advisory
- http://www.securityfocus.com/archive/1/394797Exploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-0525?
How severe is CVE-2005-0525?
How do I fix CVE-2005-0525?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2005
- CVE-2005-0519ArGoSoft FTP Server before 1.4.2.7 allows remote attackers t…
- CVE-2005-0520ArGoSoft FTP Server before 1.4.2.8 allows remote attackers t…
- CVE-2005-0521SendLink 1.5 stores sensitive information, possibly includin…
- CVE-2005-0522Chat Anywhere 2.72a stores sensitive information such as pas…
- CVE-2005-0523Format string vulnerability in ProZilla 1.3.7.3 and earlier …
- CVE-2005-0524The php_handle_iff function in image.c for PHP 4.2.2, 4.3.9,…
- CVE-2005-0526Multiple cross-site scripting (XSS) vulnerabilities in PBLan…
- CVE-2005-0527Firefox 1.0 allows remote attackers to execute arbitrary cod…
- CVE-2005-0528Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2005-0529Linux kernel 2.6.10 and 2.6.11rc1-bk6 uses different size ty…
- CVE-2005-0530Signedness error in the copy_from_read_buf function in n_tty…
- CVE-2005-0531The atm_get_addr function in addr.c for Linux kernel 2.6.10 …
Are you affected by CVE-2005-0525?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
