Out-of-bounds read in PHP - CVE-2019-11042
Published: September 20, 2019
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition within the exif_read_data() function in PHP EXIF extention. A remote attacker can create a specially crafted image file, pass it to the application, trigger out-of-bounds read error and read contents of memory on the system.
Affected software
Amazon Linux AMI
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Opensuse
Fedora
Red Hat Software Collections
Tenable.sc
php7.0 (Debian package)
php7 (Alpine package)
php7.3 (Debian package)
php
How to mitigate CVE-2019-11042
Tenable.sc - update to 5.19.0
php7.0 (Debian package) - update to 7.0.33-0+deb9u5
php7 (Alpine package) - update to 7.1.32-r0
php7.3 (Debian package) - update to 7.3.9-1~deb10u1
php - addressed in versions 7.2.21-1.fc29, 7.3.8-1.fc30
External References
Related Security Bulletins
- Amazon Linux AMI update for php71, php73
- Amazon Linux AMI update for php72
- Debian update for php7.3
- Debian update for php7.0
- OpenSUSE Linux update for php7
- Red Hat update for rh-php72-php
- Red Hat Enterprise Linux 8 update for the php:7.2 module
- Out-of-bounds read in php7 (Alpine package)
- Multiple vulnerabilities in Tenable.sc
- Red Hat Enterprise Linux 8 update for the php:7.3 module
- Fedora 29 update for php
- Fedora 30 update for php