Out-of-bounds read in PHP - CVE-2019-9022
Published: November 1, 2019
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition within the php_parserr in ext/standard/dns.c when processing DNS_CAA and DNS_ANY responses. A remote attacker controlling a malicious DNS server can trigger out-of-bounds read error and read contents of memory on the system.
Affected software
Red Hat Software Collections
php7 (Alpine package)
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
How to mitigate CVE-2019-9022
php7 (Alpine package) - update to 7.2.17-r0