Buffer overflow in PHP - CVE-2019-9641

 

Buffer overflow in PHP - CVE-2019-9641

Published: March 9, 2019 / Updated: July 17, 2020


Vulnerability identifier: #VU31148
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-9641
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in exif_process_IFD_in_TIFF.


Affected software

PHP
php7 (Alpine package)
Opensuse
Flex System Chassis Management Module (CMM)

How to mitigate CVE-2019-9641

Install update from vendor's website.

PHP - update to 7.3.3
php7 (Alpine package) - addressed in versions 7.1.30-r0, 7.2.17-r0
Flex System Chassis Management Module (CMM) - update to 2pet18c-2.5.16c

External References

Related Security Bulletins