9.8
CVE-2019-11043
- EPSS 99.41%
- Veröffentlicht 28.10.2019 15:15:13
- Zuletzt bearbeitet 03.11.2025 19:23:46
- Erkennungen
Underflow in PHP-FPM can lead to RCE
In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 19.04
Canonical ≫ Ubuntu Linux Version 19.10
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
Fedoraproject ≫ Fedora Version 29
Fedoraproject ≫ Fedora Version 30
Fedoraproject ≫ Fedora Version 31
Tenable ≫ Tenable.Sc Version < 5.19.0
Redhat ≫ Software Collections Version 1.0
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Enterprise Linux Desktop Version 6.0
Redhat ≫ Enterprise Linux Desktop Version 7.0
Redhat ≫ Enterprise Linux Eus Version 7.7
Redhat ≫ Enterprise Linux Eus Version 8.1
Redhat ≫ Enterprise Linux Eus Version 8.2
Redhat ≫ Enterprise Linux Eus Version 8.4
Redhat ≫ Enterprise Linux Eus Version 8.6
Redhat ≫ Enterprise Linux Eus Version 8.8
Redhat ≫ Enterprise Linux Eus Compute Node Version 7.7
Redhat ≫ Enterprise Linux For Arm 64 Version 8.0_aarch64
Redhat ≫ Enterprise Linux For Arm 64 Eus Version 8.1_aarch64
Redhat ≫ Enterprise Linux For Arm 64 Eus Version 8.2_aarch64
Redhat ≫ Enterprise Linux For Arm 64 Eus Version 8.4_aarch64
Redhat ≫ Enterprise Linux For Arm 64 Eus Version 8.6_aarch64
Redhat ≫ Enterprise Linux For Arm 64 Eus Version 8.8_aarch64
Redhat ≫ Enterprise Linux For Ibm Z Systems Version 6.0_s390x
Redhat ≫ Enterprise Linux For Ibm Z Systems Version 7.0_s390x
Redhat ≫ Enterprise Linux For Ibm Z Systems Version 8.0_s390x
Redhat ≫ Enterprise Linux For Ibm Z Systems Eus Version 7.7_s390x
Redhat ≫ Enterprise Linux For Ibm Z Systems Eus Version 8.1_s390x
Redhat ≫ Enterprise Linux For Ibm Z Systems Eus Version 8.2_s390x
Redhat ≫ Enterprise Linux For Ibm Z Systems Eus Version 8.4_s390x
Redhat ≫ Enterprise Linux For Ibm Z Systems Eus Version 8.6_s390x
Redhat ≫ Enterprise Linux For Ibm Z Systems Eus Version 8.8_s390x
Redhat ≫ Enterprise Linux For Power Big Endian Version 6.0_ppc64
Redhat ≫ Enterprise Linux For Power Big Endian Version 7.0_ppc64
Redhat ≫ Enterprise Linux For Power Big Endian Eus Version 7.7_ppc64
Redhat ≫ Enterprise Linux For Power Little Endian Version 7.0_ppc64le
Redhat ≫ Enterprise Linux For Power Little Endian Version 8.0_ppc64le
Redhat ≫ Enterprise Linux For Power Little Endian Eus Version 7.7_ppc64le
Redhat ≫ Enterprise Linux For Power Little Endian Eus Version 8.1_ppc64le
Redhat ≫ Enterprise Linux For Power Little Endian Eus Version 8.2_ppc64le
Redhat ≫ Enterprise Linux For Power Little Endian Eus Version 8.4_ppc64le
Redhat ≫ Enterprise Linux For Power Little Endian Eus Version 8.6_ppc64le
Redhat ≫ Enterprise Linux For Power Little Endian Eus Version 8.8_ppc64le
Redhat ≫ Enterprise Linux For Scientific Computing Version 7.0
Redhat ≫ Enterprise Linux Server Version 6.0
Redhat ≫ Enterprise Linux Server Version 7.0
Redhat ≫ Enterprise Linux Server Aus Version 7.7
Redhat ≫ Enterprise Linux Server Aus Version 8.2
Redhat ≫ Enterprise Linux Server Aus Version 8.4
Redhat ≫ Enterprise Linux Server Aus Version 8.6
Redhat ≫ Enterprise Linux Server Tus Version 7.7
Redhat ≫ Enterprise Linux Server Tus Version 8.2
Redhat ≫ Enterprise Linux Server Tus Version 8.4
Redhat ≫ Enterprise Linux Server Tus Version 8.6
Redhat ≫ Enterprise Linux Server Tus Version 8.8
Redhat ≫ Enterprise Linux Workstation Version 6.0
Redhat ≫ Enterprise Linux Workstation Version 7.0
25.03.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog
PHP FastCGI Process Manager (FPM) Buffer Overflow Vulnerability
SchwachstelleIn some versions of PHP in certain configurations of FPM setup, it is possible to cause FPM module to write past allocated buffers allowing the possibility of remote code execution.
BeschreibungApply updates per vendor instructions.
Erforderliche Maßnahmen| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 99.41% | 0.999 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
| PHP | 8.7 | 2.2 | 5.8 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
|
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
https://access.redhat.com/errata/RHSA-2019:3299
https://www.tenable.com/security/tns-2021-14
http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00011.html
http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00014.html
http://packetstormsecurity.com/files/156642/PHP-FPM-7.x-Remote-Code-Execution.html
http://seclists.org/fulldisclosure/2020/Jan/40
https://access.redhat.com/errata/RHSA-2019:3286
https://access.redhat.com/errata/RHSA-2019:3287
https://access.redhat.com/errata/RHSA-2019:3300
https://access.redhat.com/errata/RHSA-2019:3724
https://access.redhat.com/errata/RHSA-2019:3735
https://access.redhat.com/errata/RHSA-2019:3736
https://access.redhat.com/errata/RHSA-2020:0322
https://bugs.php.net/bug.php?id=78599
https://github.com/neex/phuip-fpizdam
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3W23TP6X4H7LB645FYZLUPNIRD5W3EPU/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FSNBUSPKMLUHHOADROKNG5GDWDCRHT5M/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T62LF4ZWVV7OMMIZFO6IFO5QLZKK7YRD/
https://seclists.org/bugtraq/2020/Jan/44
https://security.netapp.com/advisory/ntap-20191031-0003/
https://support.apple.com/kb/HT210919
https://support.f5.com/csp/article/K75408500?utm_source=f5support&%3Butm_medium=RSS
https://usn.ubuntu.com/4166-1/
https://usn.ubuntu.com/4166-2/
https://www.debian.org/security/2019/dsa-4552
https://www.debian.org/security/2019/dsa-4553
https://www.synology.com/security/advisory/Synology_SA_19_36
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-11043