← Back

CVE-2019-11042

nvd nist
Published: Aug 9, 2019Modified: Jun 17, 2026

JSON object

Loading...
7.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
Exploitability: 2.8 / Impact: 4.2
Source: NVD

Description

When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.31, 7.2.x below 7.2.21 and 7.3.x below 7.3.8 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.

Affected (15)

Products: Php: Php · Debian: Debian Linux · Canonical: Ubuntu Linux · +4 more
Show all products
1 product
Php
1 product
Debian Linux
1 product
Ubuntu Linux
1 product
Mac Os X
1 product
Leap
1 product
Software Collections
1 product
Tenable.sc
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Php
From 7.1.0 to 7.1.31
From 7.2.0 to 7.2.21
From 7.3.0 to 7.3.8
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 10.0
Version 8.0
Version 9.0
Configuration C
5 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 12.04
Version 14.04
Version 16.04
Version 18.04
Version 19.04
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 10.15.1
Configuration E
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 15.0
Configuration F
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 1.0
Configuration G
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 5.19.0

References (34)

Source: security@php.net
Mailing ListThird Party Advisory
Source: security@php.net
Mailing ListThird Party Advisory
Source: security@php.net
Third Party Advisory
Source: security@php.net
ExploitPatchVendor Advisory
Source: security@php.net
Mailing ListThird Party Advisory
Source: security@php.net
Mailing ListThird Party Advisory
Source: security@php.net
Mailing ListThird Party Advisory
Source: security@php.net
Mailing ListThird Party Advisory
Source: security@php.net
Third Party Advisory
Source: security@php.net
Third Party Advisory
Source: security@php.net
Third Party Advisory
Source: security@php.net
Third Party Advisory
Source: security@php.net
Third Party Advisory
Source: security@php.net
Third Party Advisory
Source: security@php.net
Third Party Advisory
Source: security@php.net
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.