{"id":"CVE-2016-10158","details":"The exif_convert_any_to_int function in ext/exif/exif.c in PHP before 5.6.30, 7.0.x before 7.0.15, and 7.1.x before 7.1.1 allows remote attackers to cause a denial of service (application crash) via crafted EXIF data that triggers an attempt to divide the minimum representable negative integer by -1.","modified":"2026-07-08T12:35:40.085566Z","published":"2017-01-24T21:59:00.133Z","related":["SUSE-SU-2017:0534-1","SUSE-SU-2017:0556-1","SUSE-SU-2017:0568-1"],"references":[{"type":"WEB","url":"http://www.securitytracker.com/id/1037659"},{"type":"WEB","url":"https://www.tenable.com/security/tns-2017-04"},{"type":"ADVISORY","url":"http://php.net/ChangeLog-5.php"},{"type":"ADVISORY","url":"http://php.net/ChangeLog-7.php"},{"type":"ADVISORY","url":"http://www.debian.org/security/2017/dsa-3783"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/95764"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:1296"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/201702-29"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20180112-0001/"},{"type":"REPORT","url":"https://bugs.php.net/bug.php?id=73737"},{"type":"FIX","url":"https://github.com/php/php-src/commit/1cda0d7c2ffb62d8331c64e703131d9cabdc03ea"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/php/php-src","events":[{"introduced":"0"},{"last_affected":"b4e4201c1c18eff67450b7d73ff028b81610e749"},{"introduced":"60fffd296abce5fc071f3c173c25a2696cf683c6"},{"last_affected":"0221e9f827632942225586687a33cfd554860d5e"},{"fixed":"1cda0d7c2ffb62d8331c64e703131d9cabdc03ea"}],"database_specific":{"cpe":["cpe:2.3:a:php:php:*:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.0:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.1:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.2:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.3:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.4:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.5:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.6:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.7:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.8:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.9:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.10:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.11:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.12:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.13:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.0.14:*:*:*:*:*:*:*","cpe:2.3:a:php:php:7.1.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"last_affected":"5.6.29"},{"introduced":"7.0.0"},{"last_affected":"7.0.0"},{"introduced":"7.0.1"},{"last_affected":"7.0.1"},{"introduced":"7.0.2"},{"last_affected":"7.0.2"},{"introduced":"7.0.3"},{"last_affected":"7.0.3"},{"introduced":"7.0.4"},{"last_affected":"7.0.4"},{"introduced":"7.0.5"},{"last_affected":"7.0.5"},{"introduced":"7.0.6"},{"last_affected":"7.0.6"},{"introduced":"7.0.7"},{"last_affected":"7.0.7"},{"introduced":"7.0.8"},{"last_affected":"7.0.8"},{"introduced":"7.0.9"},{"last_affected":"7.0.9"},{"introduced":"7.0.10"},{"last_affected":"7.0.10"},{"introduced":"7.0.11"},{"last_affected":"7.0.11"},{"introduced":"7.0.12"},{"last_affected":"7.0.12"},{"introduced":"7.0.13"},{"last_affected":"7.0.13"},{"introduced":"7.0.14"},{"last_affected":"7.0.14"},{"introduced":"7.1.0"},{"last_affected":"7.1.0"}],"source":["CPE_RANGE","CPE_STRING","REFERENCES"]}}],"versions":["7.0.0","7.0.1","7.0.10","7.0.11","7.0.12","7.0.13","7.0.14","7.0.2","7.0.3","7.0.4","7.0.5","7.0.6","7.0.7","7.0.8","7.0.9","7.1.0","php-5.6.29","php-5.6.29RC1","php-7.1.0","php-7.1.0RC6","POST_PHP7_NSAPI_REMOVAL","PRE_PHP7_NSAPI_REMOVAL","PRE_PHP7_EREG_MYSQL_REMOVALS","PRE_PHP7_REMOVALS","POST_PHP7_REMOVALS","POST_AST_MERGE","PRE_AST_MERGE","POST_64BIT_BRANCH_MERGE","PRE_64BIT_BRANCH_MERGE","POST_PHPNG_MERGE"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-10158.json","vanir_signatures_modified":"2026-07-08T12:35:40Z","vanir_signatures":[{"id":"CVE-2016-10158-527a49fb","signature_type":"Line","signature_version":"v1","source":"https://github.com/php/php-src/commit/1cda0d7c2ffb62d8331c64e703131d9cabdc03ea","target":{"file":"ext/exif/exif.c"},"deprecated":false,"digest":{"line_hashes":["164345692419806313782867716889242662623","199961379753220402556809735134877964513","81811983889484349135308472968212951300","306448116651839402360195260972894763694"],"threshold":0.9}},{"id":"CVE-2016-10158-a3bc0f1f","signature_type":"Function","signature_version":"v1","source":"https://github.com/php/php-src/commit/1cda0d7c2ffb62d8331c64e703131d9cabdc03ea","target":{"file":"ext/exif/exif.c","function":"exif_convert_any_to_int"},"deprecated":false,"digest":{"function_hash":"176999397470364082473290218156567094275","length":1196}}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}