Out-of-bounds read in PHP - CVE-2019-9639
Published: November 1, 2019
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition in the EXIF component in exif_process_IFD_in_MAKERNOTE when handling the data_len variable. A remote attacker can trigger out-of-bounds read error and read contents of memory on the system.
Affected software
Red Hat Software Collections
php7 (Alpine package)
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64
Flex System Chassis Management Module (CMM)
How to mitigate CVE-2019-9639
php7 (Alpine package) - addressed in versions 7.1.30-r0, 7.2.17-r0
Flex System Chassis Management Module (CMM) - update to 2pet18c-2.5.16c