CVE-2019-9637

Source
https://cve.org/CVERecord?id=CVE-2019-9637
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-9637.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-9637
Downstream
Related
Published
2019-03-09T00:29:00.520Z
Modified
2026-02-05T06:43:51.683888Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

An issue was discovered in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. Due to the way rename() across filesystems is implemented, it is possible that file being renamed is briefly available with wrong permissions while the rename is ongoing, thus enabling unauthorized users to access the data.

References

Affected packages

Git / github.com/php/php-src

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-9637.json"