9.8

CVE-2019-11043

Warnung
Exploit

Underflow in PHP-FPM can lead to RCE

In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Php ≫ Php Version >= 7.1.0 < 7.1.33
Php ≫ Php Version >= 7.2.0 < 7.2.24
Php ≫ Php Version >= 7.3.0 < 7.3.11
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 19.04
Canonical ≫ Ubuntu Linux Version 19.10
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
Fedoraproject ≫ Fedora Version 29
Fedoraproject ≫ Fedora Version 30
Fedoraproject ≫ Fedora Version 31
Tenable ≫ Tenable.Sc Version < 5.19.0
Redhat ≫ Software Collections Version 1.0
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Enterprise Linux Eus Version 7.7
Redhat ≫ Enterprise Linux Eus Version 8.1
Redhat ≫ Enterprise Linux Eus Version 8.2
Redhat ≫ Enterprise Linux Eus Version 8.4
Redhat ≫ Enterprise Linux Eus Version 8.6
Redhat ≫ Enterprise Linux Eus Version 8.8
Redhat ≫ Enterprise Linux For Arm 64 Version 8.0_aarch64
Redhat ≫ Enterprise Linux For Arm 64 Eus Version 8.1_aarch64
Redhat ≫ Enterprise Linux For Arm 64 Eus Version 8.2_aarch64
Redhat ≫ Enterprise Linux For Arm 64 Eus Version 8.4_aarch64
Redhat ≫ Enterprise Linux For Arm 64 Eus Version 8.6_aarch64
Redhat ≫ Enterprise Linux For Arm 64 Eus Version 8.8_aarch64

25.03.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog

PHP FastCGI Process Manager (FPM) Buffer Overflow Vulnerability

Schwachstelle

In some versions of PHP in certain configurations of FPM setup, it is possible to cause FPM module to write past allocated buffers allowing the possibility of remote code execution.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 99.41% 0.999
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
PHP 8.7 2.2 5.8
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://access.redhat.com/errata/RHSA-2019:3299
Third Party Advisory
https://www.tenable.com/security/tns-2021-14
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00011.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00014.html
Third Party Advisory
Mailing List
http://packetstormsecurity.com/files/156642/PHP-FPM-7.x-Remote-Code-Execution.html
Third Party Advisory
Exploit
VDB Entry
http://seclists.org/fulldisclosure/2020/Jan/40
Third Party Advisory
Mailing List
https://access.redhat.com/errata/RHSA-2019:3286
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:3287
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:3300
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:3724
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:3735
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:3736
Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0322
Third Party Advisory
https://bugs.php.net/bug.php?id=78599
Patch
Vendor Advisory
Exploit
Issue Tracking
https://github.com/neex/phuip-fpizdam
Third Party Advisory
Exploit
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3W23TP6X4H7LB645FYZLUPNIRD5W3EPU/
Third Party Advisory
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FSNBUSPKMLUHHOADROKNG5GDWDCRHT5M/
Third Party Advisory
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T62LF4ZWVV7OMMIZFO6IFO5QLZKK7YRD/
Third Party Advisory
Mailing List
https://seclists.org/bugtraq/2020/Jan/44
Third Party Advisory
Mailing List
https://security.netapp.com/advisory/ntap-20191031-0003/
Third Party Advisory
https://support.apple.com/kb/HT210919
Third Party Advisory
https://support.f5.com/csp/article/K75408500?utm_source=f5support&amp%3Butm_medium=RSS
Third Party Advisory
https://usn.ubuntu.com/4166-1/
Third Party Advisory
https://usn.ubuntu.com/4166-2/
Third Party Advisory
https://www.debian.org/security/2019/dsa-4552
Third Party Advisory
Mailing List
https://www.debian.org/security/2019/dsa-4553
Third Party Advisory
Mailing List
https://www.synology.com/security/advisory/Synology_SA_19_36
Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-11043
US Government Resource