Out-of-bounds read in PHP - CVE-2019-11035
Published: May 2, 2019
Vulnerability identifier: #VU18380
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-11035
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition within the exif_iif_add_value() function in PHP EXIF extension when processing certain files. An attacker can pass a specially crafted file to the application, trigger out-of-bounds read error and read contents of memory on the system or perform a denial of service attack.Affected software
PHP
Amazon Linux AMI
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Opensuse
Red Hat Software Collections
php7.0 (Debian package)
php7 (Alpine package)
Amazon Linux AMI
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Opensuse
Red Hat Software Collections
php7.0 (Debian package)
php7 (Alpine package)
How to mitigate CVE-2019-11035
Install updates from vendor's website.
PHP - addressed in versions 7.1.28, 7.2.17, 7.3.4
php7.0 (Debian package) - update to 7.0.33-0+deb9u5
php7 (Alpine package) - addressed in versions 7.1.30-r0, 7.2.18-r0
php7.0 (Debian package) - update to 7.0.33-0+deb9u5
php7 (Alpine package) - addressed in versions 7.1.30-r0, 7.2.18-r0