Malicious JPEG Images Could Trigger PHP Memory Safety Vulnerabilities
ID: 793f4d16-c47f-5232-aef2-2f159dfb1b34
STIX ID: report--793f4d16-c47f-5232-aef2-2f159dfb1b34
Feed Name: cybersecurityNews.com
Threat Score
**Executive summary:** Two critical memory-safety flaws in PHP's ext/standard image-processing functions were disclosed: CVE-2025-14177 allows leakage of uninitialized heap memory via getimagesize when processing large multi-chunk JPEG APP segments, and a heap buffer overflow in iptcembed can be triggered by streams (e.g., FIFOs) or oversized input causing out-of-bounds writes; both have practical PoCs and patches are available for affected PHP 8.1–8.5 series.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
