Out-of-bounds read in PHP - CVE-2019-11036
Published: June 14, 2019
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition in exif_process_IFD_TAG() function in PHP EXIF extension. A remote attacker can send a specially crafted file to the affected application, trigger out-of-bounds read error and read contents of memory on the system or crash the process.
Affected software
Amazon Linux AMI
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64
Fedora
Opensuse
Red Hat Software Collections
php7.0 (Debian package)
php7 (Alpine package)
php7.3 (Debian package)
php
Dell PowerProtect Cyber Recovery
How to mitigate CVE-2019-11036
php7.0 (Debian package) - update to 7.0.33-0+deb9u5
php7 (Alpine package) - addressed in versions 7.1.30-r0, 7.2.18-r0
php7.3 (Debian package) - update to 7.3.9-1~deb10u1
php - addressed in versions 7.2.18-1.fc28, 7.2.18-1.fc29, 7.3.5-1.fc30
Dell PowerProtect Cyber Recovery - update to 18.1.1.2-8
External References
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00012.html
- http://www.securityfocus.com/bid/108177
- https://bugs.php.net/bug.php?id=77950
- https://lists.debian.org/debian-lts-announce/2019/05/msg00035.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2NFXYNCXZCPYT7ZN4ZLI5EPQQW44FRRO/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3BY2XUUAN277LS7HKAOGL4DVGAELOJV3/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WN2HLPGEZEF4MFM5YC5FILZB5QEQFP3A/
- https://security.netapp.com/advisory/ntap-20190517-0003/
- https://usn.ubuntu.com/3566-2/
- https://usn.ubuntu.com/4009-1/
Related Security Bulletins
- Amazon Linux AMI update for php71, php72, php73
- OpenSUSE Linux update for php7
- Debian update for php7.3
- Debian update for php7.0
- Red Hat update for rh-php72-php
- Red Hat Enterprise Linux 8 update for the php:7.2 module
- Out-of-bounds read in php7 (Alpine package)
- Multiple vulnerabilities in Dell EMC Cyber Recovery
- Fedora 29 update for php
- Fedora 28 update for php
- Fedora 30 update for php