← Back

CVE-2019-11043

nvd nist
Published: Oct 28, 2019Modified: Jun 17, 2026CISA KEV

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.

Affected (66)

Products: Php: Php · Canonical: Ubuntu Linux · Debian: Debian Linux · +3 more
Show all products
1 product
Php
1 product
Ubuntu Linux
1 product
Debian Linux
1 product
Fedora
1 product
Tenable.sc
18 products
Enterprise Linux
Enterprise Linux Desktop
Enterprise Linux Eus
Enterprise Linux Eus Compute Node
Enterprise Linux For Arm 64
Enterprise Linux For Arm 64 Eus
Enterprise Linux Server
Enterprise Linux Server Aus
Enterprise Linux Server Tus
Enterprise Linux Workstation
Software Collections
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Php
From 7.1.0 to 7.1.33
From 7.2.0 to 7.2.24
From 7.3.0 to 7.3.11
Configuration B
6 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 12.04
Version 14.04
Version 16.04
Version 18.04
Version 19.04
Version 19.10
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 10.0
Version 9.0
Configuration D
3 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 29
Version 30
Version 31
Configuration E
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 5.19.0
Configuration F
51 vulnerable
Vulnerable SoftwareAffected Versions
Version 8.0
Redhat
Version 6.0
Version 7.0
Redhat
Version 7.7
Version 8.1
Version 8.2
Version 8.4
Version 8.6
Version 8.8
Version 7.7
Version 8.0_aarch64
Redhat
Version 8.1_aarch64
Version 8.2_aarch64
Version 8.4_aarch64
Version 8.6_aarch64
Version 8.8_aarch64
Redhat
Version 6.0_s390x
Version 7.0_s390x
Version 8.0_s390x
Redhat
Version 7.7_s390x
Version 8.1_s390x
Version 8.2_s390x
Version 8.4_s390x
Version 8.6_s390x
Version 8.8_s390x
Redhat
Version 6.0_ppc64
Version 7.0_ppc64
Version 7.7_ppc64
Redhat
Version 7.0_ppc64le
Version 8.0_ppc64le
Redhat
Version 7.7_ppc64le
Version 8.1_ppc64le
Version 8.2_ppc64le
Version 8.4_ppc64le
Version 8.6_ppc64le
Version 8.8_ppc64le
Version 7.0
Redhat
Version 6.0
Version 7.0
Redhat
Version 7.7
Version 8.2
Version 8.4
Version 8.6
Redhat
Version 7.7
Version 8.2
Version 8.4
Version 8.6
Version 8.8
Redhat
Version 6.0
Version 7.0
Version 1.0

References (55)

Source: security@php.net
Mailing ListThird Party Advisory
Source: security@php.net
Mailing ListThird Party Advisory
Source: security@php.net
ExploitThird Party AdvisoryVDB Entry
Source: security@php.net
Mailing ListThird Party Advisory
Source: security@php.net
Third Party Advisory
Source: security@php.net
Third Party Advisory
Source: security@php.net
Third Party Advisory
Source: security@php.net
Third Party Advisory
Source: security@php.net
Third Party Advisory
Source: security@php.net
Third Party Advisory
Source: security@php.net
Third Party Advisory
Source: security@php.net
Third Party Advisory
Source: security@php.net
ExploitIssue TrackingPatchVendor Advisory
Source: security@php.net
ExploitThird Party Advisory
Source: security@php.net
Mailing ListThird Party Advisory
Source: security@php.net
Third Party Advisory
Source: security@php.net
Third Party Advisory
Source: security@php.net
Third Party Advisory
Source: security@php.net
Third Party Advisory
Source: security@php.net
Mailing ListThird Party Advisory
Source: security@php.net
Mailing ListThird Party Advisory
Source: security@php.net
Third Party Advisory
Source: security@php.net
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.