An issue was discovered in PHP 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.2. dnsgetrecord misparses a DNS response, which can allow a hostile DNS server to cause PHP to misuse memcpy, leading to read operations going past the buffer allocated for DNS data. This affects phpparserr in ext/standard/dns.c for DNSCAA and DNS_ANY queries.
{
"versions": [
{
"introduced": "7.0.0"
},
{
"fixed": "7.1.26"
},
{
"introduced": "7.2.0"
},
{
"fixed": "7.2.14"
},
{
"introduced": "7.3.0"
},
{
"fixed": "7.3.2"
},
{
"introduced": "0"
},
{
"last_affected": "8.0"
}
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-9022.json"
[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "12.04"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "14.04"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "16.04"
}
]
}
]