mail() may release string with refcount==1 twice
Published Dec 23, 2019
9.8
CRITICALCVSS 3.1
EPSS 4.22%
Description
In PHP versions 7.3.x below 7.3.13 and 7.4.0 on Windows, when supplying custom headers to mail() function, due to mistake introduced in commit 78f4b4a2dcf92ddbccea1bb95f8390a18ac3342e, if the header is supplied in lowercase, this can result in double-freeing certain memory locations.
Affected products
-
- Version 7.3.xStatusaffectedConstraints<7.3.13
- Version 7.4.xStatusaffectedConstraints<7.4.1
- Version
Configuration 1
Configuration 2
- 30
- 31
Configuration 3
- 10.0
Configuration 4
- < 5.19.0
No data.
Red Hat Enterprise Linux 5
php
Not affected
Red Hat Enterprise Linux 5
php53
Not affected
Red Hat Enterprise Linux 6
php
Not affected
Red Hat Enterprise Linux 7
php
Not affected
Red Hat Enterprise Linux 8
php:7.2/php
Not affected
Red Hat Enterprise Linux 8
php:7.3/php
Not affected
Red Hat Software Collections
rh-php72-php
Not affected
Red Hat Software Collections
rh-php73-php
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | php | Not affected | n/a |
| Red Hat Enterprise Linux 5 | php53 | Not affected | n/a |
| Red Hat Enterprise Linux 6 | php | Not affected | n/a |
| Red Hat Enterprise Linux 7 | php | Not affected | n/a |
| Red Hat Enterprise Linux 8 | php:7.2/php | Not affected | n/a |
| Red Hat Enterprise Linux 8 | php:7.3/php | Not affected | n/a |
| Red Hat Software Collections | rh-php72-php | Not affected | n/a |
| Red Hat Software Collections | rh-php73-php | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue doesn't affect any PHP version as shipped with Red Hat Enterprise Linux or Red Hat Software Collection versions, as the flawed component is exclusive to Windows.
References (11)
- https://access.redhat.com/security/cve/CVE-2019-11049 Vendor Advisory
- https://bugs.php.net/bug.php?id=78943 x_refsource_MISCMailing ListPatchVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1788586 Issue Tracking
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N7GCOAE6KVHYJ3UQ4KLPLTGSLX6IRVRN/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XWRQPYXVG43Q7DXMXH6UVWMKWGUW552F/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2019-11049
- https://seclists.org/bugtraq/2020/Feb/27 mailing-listx_refsource_BUGTRAQMailing ListThird Party Advisory
- https://security.netapp.com/advisory/ntap-20200103-0002/ x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-11049
- https://www.debian.org/security/2020/dsa-4626 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.tenable.com/security/tns-2021-14 x_refsource_CONFIRMThird Party Advisory
Change history (0)
No recorded changes yet.