CVE-2018-14883: Canonical Ubuntu Linux

High severity, CVSS 7.5. EPSS: 8.9% chance of exploitation in the next 30 days.

An issue was discovered in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and 7.2.x before 7.2.8. An Integer Overflow leads to a heap-based buffer over-read in exif_thumbnail_extract of exif.c.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 16.04 only; version 18.04 only
  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Netapp Storage Automation Store: affected versions not specified
  • PHP PHP: before 5.6.37 (fixed in 5.6.37); from 7.0.0, before 7.0.31 (fixed in 7.0.31); from 7.1.0, before 7.1.20 (fixed in 7.1.20); from 7.2.0, before 7.2.8 (fixed in 7.2.8)

Published 2018-08-03. Last modified 2026-06-17.