5.9

CVE-2019-11045

Exploit

DirectoryIterator class silently truncates after a null byte

In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP DirectoryIterator class accepts filenames with embedded \0 byte and treats them as terminating at that byte. This could lead to security vulnerabilities, e.g. in applications checking paths that the code is allowed to access.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Php ≫ Php Version >= 7.2.0 <= 7.2.26
Php ≫ Php Version >= 7.3.0 <= 7.3.13
Php ≫ Php Version 7.4.0
Fedoraproject ≫ Fedora Version 30
Fedoraproject ≫ Fedora Version 31
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
Opensuse ≫ Leap Version 15.1
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition -
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 19.04
Canonical ≫ Ubuntu Linux Version 19.10
Tenable ≫ Security Center Version < 5.19.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 8.82% 0.945
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.9 2.2 3.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
PHP 3.7 2.2 1.4
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
CWE-170 Improper Null Termination

The product does not terminate or incorrectly terminates a string or array with a null character or equivalent terminator.

CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

https://www.tenable.com/security/tns-2021-14
Third Party Advisory
https://security.netapp.com/advisory/ntap-20200103-0002/
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00036.html
Third Party Advisory
Mailing List
https://bugs.php.net/bug.php?id=78863
Patch
Vendor Advisory
Exploit
Mailing List
https://lists.debian.org/debian-lts-announce/2019/12/msg00034.html
Third Party Advisory
Mailing List
https://usn.ubuntu.com/4239-1/
Third Party Advisory
https://www.debian.org/security/2020/dsa-4626
Third Party Advisory
https://www.debian.org/security/2020/dsa-4628
Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N7GCOAE6KVHYJ3UQ4KLPLTGSLX6IRVRN/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XWRQPYXVG43Q7DXMXH6UVWMKWGUW552F/
https://seclists.org/bugtraq/2020/Feb/27
Third Party Advisory
Mailing List
https://seclists.org/bugtraq/2020/Feb/31
Third Party Advisory
Mailing List
https://seclists.org/bugtraq/2021/Jan/3
Third Party Advisory
Mailing List