heap-buffer-overflow on exif_process_user_comment in EXIF extension
Published Aug 9, 2019
7.1
HIGHCVSS 3.1
EPSS 4.42%
Description
When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.31, 7.2.x below 7.2.21 and 7.3.x below 7.3.8 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.
Affected products
-
- Version 7.1.x below 7.1.31StatusaffectedConstraints-
- Version 7.2.x below 7.2.21StatusaffectedConstraints-
- Version 7.3.x below 7.3.8StatusaffectedConstraints-
- Version
Configuration 1
Configuration 2
- 8.0
- 9.0
- 10.0
Configuration 3
- 12.04
- 14.04
- 16.04
- 18.04
- 19.04
Configuration 6
- 1.0
Configuration 7
- < 5.19.0
No data.
Red Hat Enterprise Linux 8
php:7.2-8020020191108065827.2c7ca891
Fixed · RHSA-2020:1624
Red Hat Enterprise Linux 8
php:7.3-8020020200715124551.ceb1cf90
Fixed · RHSA-2020:3662
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-php72-php-0:7.2.24-1.el7
Fixed · RHSA-2019:3299
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS
rh-php72-php-0:7.2.24-1.el7
Fixed · RHSA-2019:3299
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-php72-php-0:7.2.24-1.el7
Fixed · RHSA-2019:3299
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-php72-php-0:7.2.24-1.el7
Fixed · RHSA-2019:3299
Red Hat Enterprise Linux 5
php
Out of support scope
Red Hat Enterprise Linux 5
php53
Out of support scope
Red Hat Enterprise Linux 6
php
Out of support scope
Red Hat Enterprise Linux 7
php
Fix deferred
Red Hat Software Collections
rh-php70-php
Fix deferred
Red Hat Software Collections
rh-php71-php
Out of support scope
Red Hat Software Collections
rh-php73-php
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | php:7.2-8020020191108065827.2c7ca891 | Fixed | RHSA-2020:1624 |
| Red Hat Enterprise Linux 8 | php:7.3-8020020200715124551.ceb1cf90 | Fixed | RHSA-2020:3662 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-php72-php-0:7.2.24-1.el7 | Fixed | RHSA-2019:3299 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS | rh-php72-php-0:7.2.24-1.el7 | Fixed | RHSA-2019:3299 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-php72-php-0:7.2.24-1.el7 | Fixed | RHSA-2019:3299 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-php72-php-0:7.2.24-1.el7 | Fixed | RHSA-2019:3299 |
| Red Hat Enterprise Linux 5 | php | Out of support scope | n/a |
| Red Hat Enterprise Linux 5 | php53 | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | php | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | php | Fix deferred | n/a |
| Red Hat Software Collections | rh-php70-php | Fix deferred | n/a |
| Red Hat Software Collections | rh-php71-php | Out of support scope | n/a |
| Red Hat Software Collections | rh-php73-php | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (22)
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00019.html vendor-advisoryx_refsource_SUSEThird Party Advisory
- http://seclists.org/fulldisclosure/2019/Oct/15 mailing-listx_refsource_FULLDISCMailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2019/Oct/55 mailing-listx_refsource_FULLDISCMailing ListThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3299 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-11042 Vendor Advisory
- https://bugs.php.net/bug.php?id=78256 x_refsource_CONFIRMExploitPatchVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1739465 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-2750 Advisory
- https://lists.debian.org/debian-lts-announce/2019/08/msg00010.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-11042
- https://seclists.org/bugtraq/2019/Oct/9 mailing-listx_refsource_BUGTRAQMailing ListThird Party Advisory
- https://seclists.org/bugtraq/2019/Sep/35 mailing-listx_refsource_BUGTRAQMailing ListThird Party Advisory
- https://seclists.org/bugtraq/2019/Sep/38 mailing-listx_refsource_BUGTRAQMailing ListThird Party Advisory
- https://security.netapp.com/advisory/ntap-20190822-0003/ x_refsource_CONFIRMThird Party Advisory
- https://support.apple.com/kb/HT210634 x_refsource_CONFIRMThird Party Advisory
- https://support.apple.com/kb/HT210722 x_refsource_CONFIRMThird Party Advisory
- https://usn.ubuntu.com/4097-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/4097-2/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-11042
- https://www.debian.org/security/2019/dsa-4527 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.debian.org/security/2019/dsa-4529 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.tenable.com/security/tns-2021-14 x_refsource_CONFIRMThird Party Advisory
Change history (0)
No recorded changes yet.