php: Out-of-bounds read in base64_decode_xmlrpc in ext/xmlrpc/libxmlrpc/base64.c
Published Feb 22, 2019
7.5
HIGHCVSS 3.0
EPSS 7.12%
Description
An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. xmlrpc_decode() can allow a hostile XMLRPC server to cause PHP to read memory outside of allocated areas in base64_decode_xmlrpc in ext/xmlrpc/libxmlrpc/base64.c.
Affected products
No data.
Configuration 1
Configuration 2
- 9.0
Configuration 3
- 12.04
- 14.04
- 16.04
Configuration 4
- n/a
No data.
Red Hat Enterprise Linux 7
php-0:5.4.16-48.el7
Fixed · RHSA-2020:1112
Red Hat Enterprise Linux 8
php:7.2-8020020191108065827.2c7ca891
Fixed · RHSA-2020:1624
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-php71-php-0:7.1.30-1.el7
Fixed · RHSA-2019:2519
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-php72-php-0:7.2.24-1.el7
Fixed · RHSA-2019:3299
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS
rh-php71-php-0:7.1.30-1.el7
Fixed · RHSA-2019:2519
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS
rh-php71-php-0:7.1.30-1.el7
Fixed · RHSA-2019:2519
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS
rh-php72-php-0:7.2.24-1.el7
Fixed · RHSA-2019:3299
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-php71-php-0:7.1.30-1.el7
Fixed · RHSA-2019:2519
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-php72-php-0:7.2.24-1.el7
Fixed · RHSA-2019:3299
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-php72-php-0:7.2.24-1.el7
Fixed · RHSA-2019:3299
Red Hat Enterprise Linux 5
php
Out of support scope
Red Hat Enterprise Linux 6
php
Out of support scope
Red Hat Software Collections
rh-php70-php
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | php-0:5.4.16-48.el7 | Fixed | RHSA-2020:1112 |
| Red Hat Enterprise Linux 8 | php:7.2-8020020191108065827.2c7ca891 | Fixed | RHSA-2020:1624 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-php71-php-0:7.1.30-1.el7 | Fixed | RHSA-2019:2519 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-php72-php-0:7.2.24-1.el7 | Fixed | RHSA-2019:3299 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS | rh-php71-php-0:7.1.30-1.el7 | Fixed | RHSA-2019:2519 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS | rh-php71-php-0:7.1.30-1.el7 | Fixed | RHSA-2019:2519 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS | rh-php72-php-0:7.2.24-1.el7 | Fixed | RHSA-2019:3299 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-php71-php-0:7.1.30-1.el7 | Fixed | RHSA-2019:2519 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-php72-php-0:7.2.24-1.el7 | Fixed | RHSA-2019:3299 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-php72-php-0:7.2.24-1.el7 | Fixed | RHSA-2019:3299 |
| Red Hat Enterprise Linux 5 | php | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | php | Out of support scope | n/a |
| Red Hat Software Collections | rh-php70-php | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue affects the versions of php as shipped with Red Hat Enterprise Linux 5, 6, and 7. Red Hat Enterprise Linux 5 is now in Extended Life Phase of the support and maintenance life cycle. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/. Red Hat Enterprise Linux 6 is now in Maintenance Support 2 Phase of the support and maintenance life cycle. This has been rated as having a security impact of Low, and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.
References (16)
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00083.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00104.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00041.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00044.html vendor-advisoryx_refsource_SUSE
- http://www.securityfocus.com/bid/107156 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2019:2519 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2019:3299 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2019-9024 Vendor Advisory
- https://bugs.php.net/bug.php?id=77380 x_refsource_MISCExploitIssue TrackingPatchVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1685404 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2019-9024
- https://security.netapp.com/advisory/ntap-20190321-0001/ x_refsource_CONFIRMThird Party Advisory
- https://usn.ubuntu.com/3902-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3902-2/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-9024
- https://www.debian.org/security/2019/dsa-4398 vendor-advisoryx_refsource_DEBIANThird Party Advisory
Change history (0)
No recorded changes yet.