← Back

CVE-2019-11049

nvd nist
Published: Dec 23, 2019Modified: Jun 17, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

In PHP versions 7.3.x below 7.3.13 and 7.4.0 on Windows, when supplying custom headers to mail() function, due to mistake introduced in commit 78f4b4a2dcf92ddbccea1bb95f8390a18ac3342e, if the header is supplied in lowercase, this can result in double-freeing certain memory locations.

Affected (6)

Products: Php: Php · Fedoraproject: Fedora · Debian: Debian Linux · +1 more
Show all products
1 product
Php
1 product
Fedora
1 product
Debian Linux
1 product
Securitycenter
Configuration A
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Php
From 7.3.0 to 7.3.13
Version 7.4.0
Running on/withPlatform Versions
Microsoft
Windows
All versions
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 30
Version 31
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 10.0
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 5.19.0

References (14)

Source: security@php.net
Mailing ListPatchVendor Advisory
Source: security@php.net
Mailing ListThird Party Advisory
Source: security@php.net
Third Party Advisory
Source: security@php.net
Third Party Advisory
Source: security@php.net
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.