Buffer overflow in PHP - CVE-2019-9641
Published: March 9, 2019 / Updated: July 17, 2020
Vulnerability identifier: #VU31148
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-9641
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in exif_process_IFD_in_TIFF.
Affected software
PHP
php7 (Alpine package)
Opensuse
Flex System Chassis Management Module (CMM)
php7 (Alpine package)
Opensuse
Flex System Chassis Management Module (CMM)
How to mitigate CVE-2019-9641
Install update from vendor's website.
PHP - update to 7.3.3
php7 (Alpine package) - addressed in versions 7.1.30-r0, 7.2.17-r0
Flex System Chassis Management Module (CMM) - update to 2pet18c-2.5.16c
php7 (Alpine package) - addressed in versions 7.1.30-r0, 7.2.17-r0
Flex System Chassis Management Module (CMM) - update to 2pet18c-2.5.16c
External References
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00083.html
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00104.html
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00041.html
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00044.html
- https://bugs.php.net/bug.php?id=77509
- https://lists.debian.org/debian-lts-announce/2019/03/msg00043.html
- https://security.netapp.com/advisory/ntap-20190502-0007/
- https://usn.ubuntu.com/3922-1/
- https://usn.ubuntu.com/3922-2/
- https://usn.ubuntu.com/3922-3/
- https://www.debian.org/security/2019/dsa-4403