CVE-2019-11043

Source
https://nvd.nist.gov/vuln/detail/CVE-2019-11043
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-11043.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-11043
Related
Published
2019-10-28T15:15:13Z
Modified
2024-09-02T23:07:10Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.

References

Affected packages

Git / github.com/php/php-src

Affected ranges

Type
GIT
Repo
https://github.com/php/php-src
Events