← Back

CVE-2019-11045

nvd nist
Published: Dec 23, 2019Modified: Jun 17, 2026

JSON object

Loading...
5.9
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.2 / Impact: 3.6
Source: NVD

Description

In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP DirectoryIterator class accepts filenames with embedded \0 byte and treats them as terminating at that byte. This could lead to security vulnerabilities, e.g. in applications checking paths that the code is allowed to access.

Affected (16)

Products: Php: Php · Fedoraproject: Fedora · Debian: Debian Linux · +3 more
Show all products
1 product
Php
1 product
Fedora
1 product
Debian Linux
1 product
Leap
1 product
Ubuntu Linux
1 product
Securitycenter
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Php
From 7.2.0 to 7.2.26
From 7.3.0 to 7.3.13
Version 7.4.0
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 30
Version 31
Configuration C
3 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 10.0
Version 8.0
Version 9.0
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 15.1
Configuration E
6 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 12.04
Version 14.04
Version 16.04
Version 18.04
Version 19.04
Version 19.10
Configuration F
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 5.19.0

References (26)

Source: security@php.net
Mailing ListThird Party Advisory
Source: security@php.net
ExploitMailing ListPatchVendor Advisory
Source: security@php.net
Mailing ListThird Party Advisory
Source: security@php.net
Mailing ListThird Party Advisory
Source: security@php.net
Mailing ListThird Party Advisory
Source: security@php.net
Mailing ListThird Party Advisory
Source: security@php.net
Third Party Advisory
Source: security@php.net
Third Party Advisory
Source: security@php.net
Third Party Advisory
Source: security@php.net
Third Party Advisory
Source: security@php.net
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.