CVE-2019-11040

Related Vulnerabilities: CVE-2019-11040  

Impact: Moderate Public Date: 2019-06-18 CWE: CWE-190->CWE-400 Bugzilla: 1724154: CVE-2019-11040 php: information disclosue in function exif_read_data() leads to denial of service When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.

The MITRE CVE dictionary describes this issue as:

When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.

Find out more about CVE-2019-11040 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v3 metrics

NOTE: The following CVSS v3 metrics and score provided are preliminary and subject to review.

CVSS3 Base Score 6.5
CVSS3 Base Metrics CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality Low
Integrity Impact None
Availability Impact Low

Affected Packages State

Platform Package State
Red Hat Software Collections for Red Hat Enterprise Linux rh-php70-php Not affected
Red Hat Software Collections for Red Hat Enterprise Linux rh-php72-php Under investigation
Red Hat Software Collections for Red Hat Enterprise Linux rh-php71-php Under investigation
Red Hat Enterprise Linux 8 php Under investigation
Red Hat Enterprise Linux 8 php:7.2/php Under investigation
Red Hat Enterprise Linux 7 php Not affected
Red Hat Enterprise Linux 6 php Not affected
Red Hat Enterprise Linux 5 php53 Not affected
Red Hat Enterprise Linux 5 php Not affected