#VU33364 Out-of-bounds read in Fedoraproject products - CVE-2019-11047

 

#VU33364 Out-of-bounds read in Fedoraproject products - CVE-2019-11047

Published: December 23, 2019 / Updated: August 4, 2020


Vulnerability identifier: #VU33364
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2019-11047
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
PHP
Debian Linux
Fedora
Software vendor:
PHP Group
Debian
Fedoraproject

Description

The vulnerability allows a remote non-authenticated attacker to #BASIC_IMPACT#.

When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.


Remediation

Install update from vendor's website.

External links