Out-of-bounds read in PHP - CVE-2019-9640
Published: September 20, 2019
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition in exif_process_SOFn within the PHP EXIF component. A remote attacker can create a specially crafted image file, pass it to the affected application, trigger out-of-bounds read error and read contents of memory on the system.
Affected software
Amazon Linux AMI
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64
Red Hat Software Collections
php7 (Alpine package)
Flex System Chassis Management Module (CMM)
How to mitigate CVE-2019-9640
php7 (Alpine package) - addressed in versions 7.1.30-r0, 7.2.17-r0
Flex System Chassis Management Module (CMM) - update to 2pet18c-2.5.16c