9.1

CVE-2019-11036

When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.29, 7.2.x below 7.2.18 and 7.3.x below 7.3.5 can be caused to read past allocated buffer in exif_process_IFD_TAG function. This may lead to information disclosure or crash.

Data is provided by the National Vulnerability Database (NVD)
PhpPhp Version >= 7.1.0 < 7.1.29
PhpPhp Version >= 7.2.0 < 7.2.18
PhpPhp Version >= 7.3.0 < 7.3.5
FedoraprojectFedora Version28
FedoraprojectFedora Version29
FedoraprojectFedora Version30
RedhatSoftware Collections Version1.0
CanonicalUbuntu Linux Version12.04 SwEditionesm
CanonicalUbuntu Linux Version14.04 SwEditionesm
CanonicalUbuntu Linux Version16.04 SwEditionlts
CanonicalUbuntu Linux Version18.04 SwEditionlts
CanonicalUbuntu Linux Version18.10
CanonicalUbuntu Linux Version19.04
DebianDebian Linux Version8.0
DebianDebian Linux Version9.0
DebianDebian Linux Version10.0
OpensuseLeap Version15.0
OpensuseLeap Version15.1
OpensuseLeap Version42.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.45% 0.801
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.1 3.9 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
nvd@nist.gov 6.4 10 4.9
AV:N/AC:L/Au:N/C:P/I:N/A:P
security@php.net 4.8 2.2 2.5
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L
CWE-125 Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

CWE-126 Buffer Over-read

The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.

https://usn.ubuntu.com/3566-2/
Third Party Advisory
https://seclists.org/bugtraq/2019/Sep/38
Third Party Advisory
Mailing List
http://www.securityfocus.com/bid/108177
Third Party Advisory
VDB Entry
https://bugs.php.net/bug.php?id=77950
Vendor Advisory
Mailing List
https://seclists.org/bugtraq/2019/Sep/35
Third Party Advisory
Mailing List
https://usn.ubuntu.com/4009-1/
Third Party Advisory