Weaponized JPEG Images Could Enable Exploitation of PHP Memory Flaws
ID: da219bd7-c073-5d89-a0d9-21b120b16eb1
STIX ID: report--da219bd7-c073-5d89-a0d9-21b120b16eb1
Feed Name: Cyber Press
**Executive summary:** Researchers discovered two memory-safety flaws in PHP's JPEG handling—CVE-2025-14177 in getimagesize() that can leak heap memory via multi-chunk APP segments, and a heap buffer overflow in iptcembed() that can be triggered by FIFO/pipe or race conditions—affecting multiple PHP 8.x releases; both were responsibly disclosed and patched, and users processing untrusted JPEGs should upgrade to the fixed versions and avoid passing untrusted files via php://filter or FIFO-backed paths until patched.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
