9.8

CVE-2019-11049

mail() may release string with refcount==1 twice

In PHP versions 7.3.x below 7.3.13 and 7.4.0 on Windows, when supplying custom headers to mail() function, due to mistake introduced in commit 78f4b4a2dcf92ddbccea1bb95f8390a18ac3342e, if the header is supplied in lowercase, this can result in double-freeing certain memory locations.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Php ≫ Php Version >= 7.3.0 <= 7.3.13
   Microsoft ≫ Windows Version -
Php ≫ Php Version 7.4.0
   Microsoft ≫ Windows Version -
Fedoraproject ≫ Fedora Version 30
Fedoraproject ≫ Fedora Version 31
Debian ≫ Debian Linux Version 10.0
Tenable ≫ Security Center Version < 5.19.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.22% 0.9
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
PHP 6.5 2.2 4.2
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
CWE-415 Double Free

The product calls free() twice on the same memory address.

https://www.tenable.com/security/tns-2021-14
Third Party Advisory
https://security.netapp.com/advisory/ntap-20200103-0002/
Third Party Advisory
https://www.debian.org/security/2020/dsa-4626
Third Party Advisory
https://bugs.php.net/bug.php?id=78943
Patch
Vendor Advisory
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N7GCOAE6KVHYJ3UQ4KLPLTGSLX6IRVRN/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XWRQPYXVG43Q7DXMXH6UVWMKWGUW552F/
https://seclists.org/bugtraq/2020/Feb/27
Third Party Advisory
Mailing List