← Back

CVE-2019-11044

nvd nist
Published: Dec 23, 2019Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 on Windows, PHP link() function accepts filenames with embedded \0 byte and treats them as terminating at that byte. This could lead to security vulnerabilities, e.g. in applications checking paths that the code is allowed to access.

Affected (6)

1 product
Php
1 product
Securitycenter
1 product
Fedora
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Php
From 7.2.0 to 7.2.26
From 7.3.0 to 7.3.13
Version 7.4.0
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 5.19.0
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 30
Version 31

Timeline

No history available yet.