Heap over-read in PHP EXIF extension
Published Apr 18, 2019
9.1
CRITICALCVSS 3.1
EPSS 4.09%
Description
When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.28, 7.2.x below 7.2.17 and 7.3.x below 7.3.4 can be caused to read past allocated buffer in exif_process_IFD_TAG function. This may lead to information disclosure or crash.
Affected products
-
- Version 7.1.xStatusaffectedConstraints<7.1.28
- Version 7.2.xStatusaffectedConstraints<7.2.17
- Version 7.3.xStatusaffectedConstraints<7.3.4
- Version
Configuration 1
Configuration 2
- 12.04
- 14.04
- 16.04
- 18.04
- 18.10
- 19.04
Configuration 3
- n/a
Configuration 4
- 1.0
Configuration 5
- 8.0
- 9.0
No data.
Red Hat Enterprise Linux 8
php:7.2-8020020191108065827.2c7ca891
Fixed · RHSA-2020:1624
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-php71-php-0:7.1.30-1.el7
Fixed · RHSA-2019:2519
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-php72-php-0:7.2.24-1.el7
Fixed · RHSA-2019:3299
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS
rh-php71-php-0:7.1.30-1.el7
Fixed · RHSA-2019:2519
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS
rh-php71-php-0:7.1.30-1.el7
Fixed · RHSA-2019:2519
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS
rh-php72-php-0:7.2.24-1.el7
Fixed · RHSA-2019:3299
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-php71-php-0:7.1.30-1.el7
Fixed · RHSA-2019:2519
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-php72-php-0:7.2.24-1.el7
Fixed · RHSA-2019:3299
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-php72-php-0:7.2.24-1.el7
Fixed · RHSA-2019:3299
Red Hat Enterprise Linux 5
php
Will not fix
Red Hat Enterprise Linux 5
php53
Will not fix
Red Hat Enterprise Linux 6
php
Will not fix
Red Hat Enterprise Linux 7
php
Fix deferred
Red Hat Software Collections
rh-php70-php
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | php:7.2-8020020191108065827.2c7ca891 | Fixed | RHSA-2020:1624 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-php71-php-0:7.1.30-1.el7 | Fixed | RHSA-2019:2519 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-php72-php-0:7.2.24-1.el7 | Fixed | RHSA-2019:3299 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS | rh-php71-php-0:7.1.30-1.el7 | Fixed | RHSA-2019:2519 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS | rh-php71-php-0:7.1.30-1.el7 | Fixed | RHSA-2019:2519 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS | rh-php72-php-0:7.2.24-1.el7 | Fixed | RHSA-2019:3299 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-php71-php-0:7.1.30-1.el7 | Fixed | RHSA-2019:2519 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-php72-php-0:7.2.24-1.el7 | Fixed | RHSA-2019:3299 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-php72-php-0:7.2.24-1.el7 | Fixed | RHSA-2019:3299 |
| Red Hat Enterprise Linux 5 | php | Will not fix | n/a |
| Red Hat Enterprise Linux 5 | php53 | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | php | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | php | Fix deferred | n/a |
| Red Hat Software Collections | rh-php70-php | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (19)
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00010.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00012.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00041.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00044.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2519 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3299 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-11034 Vendor Advisory
- https://bugs.php.net/bug.php?id=77753 x_refsource_MISCPatchVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1702256 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-2742 Advisory
- https://lists.debian.org/debian-lts-announce/2019/05/msg00035.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-11034
- https://seclists.org/bugtraq/2019/Sep/38 mailing-listx_refsource_BUGTRAQMailing ListThird Party Advisory
- https://security.netapp.com/advisory/ntap-20190502-0001/ x_refsource_CONFIRMThird Party Advisory
- https://support.f5.com/csp/article/K44590877 x_refsource_CONFIRMThird Party Advisory
- https://usn.ubuntu.com/3953-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3953-2/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-11034
- https://www.debian.org/security/2019/dsa-4529 vendor-advisoryx_refsource_DEBIANThird Party Advisory
Change history (0)
No recorded changes yet.