Impact: Moderate Public Date: 2019-06-18 CWE: CWE-190->CWE-400 Bugzilla: 1724154: CVE-2019-11040 php: information disclosue in function exif_read_data() leads to denial of service When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.
The MITRE CVE dictionary describes this issue as:
Find out more about CVE-2019-11040 from the MITRE CVE dictionary dictionary and NIST NVD.
NOTE: The following CVSS v3 metrics and score provided are preliminary and subject to review.
CVSS3 Base Score | 6.5 |
---|---|
CVSS3 Base Metrics | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L |
Attack Vector | Network |
Attack Complexity | Low |
Privileges Required | None |
User Interaction | None |
Scope | Unchanged |
Confidentiality | Low |
Integrity Impact | None |
Availability Impact | Low |
Platform | Package | State |
---|---|---|
Red Hat Software Collections for Red Hat Enterprise Linux | rh-php70-php | Not affected |
Red Hat Software Collections for Red Hat Enterprise Linux | rh-php72-php | Under investigation |
Red Hat Software Collections for Red Hat Enterprise Linux | rh-php71-php | Under investigation |
Red Hat Enterprise Linux 8 | php | Under investigation |
Red Hat Enterprise Linux 8 | php:7.2/php | Under investigation |
Red Hat Enterprise Linux 7 | php | Not affected |
Red Hat Enterprise Linux 6 | php | Not affected |
Red Hat Enterprise Linux 5 | php53 | Not affected |
Red Hat Enterprise Linux 5 | php | Not affected |