

Rewterz Threat Advisory – CVE-2018-0466 – Rockwell Automation Stratix 5400/5410/5700/8000/8300 and ArmorStratix 5700
April 5, 2019
Rewterz Threat Advisory – CVE-2018-1356 – Fortinet FortiSandbox “back_url” Cross-Site Scripting Vulnerability
April 5, 2019
Rewterz Threat Advisory – CVE-2018-0466 – Rockwell Automation Stratix 5400/5410/5700/8000/8300 and ArmorStratix 5700
April 5, 2019
Rewterz Threat Advisory – CVE-2018-1356 – Fortinet FortiSandbox “back_url” Cross-Site Scripting Vulnerability
April 5, 2019Severity
Medium
Analysis Summary
1) An error within the “exif_process_IFD_in_MAKERNOTE()” function (ext/exif/exif.c) can be exploited to cause an out-of-bounds read memory access.
2) An error within the “exif_iif_add_value()” function (ext/exif/exif.c) can be exploited to cause an out-of-bounds read memory access.
Impact
Denial of Service
Affected Vendors
PHP Group
Affected Products
- PHP 7.1.x
- PHP 7.2.x
Remediation
Update to version 7.1.28 or 7.2.17