9.1
CVSSv3

CVE-2019-11039

Published: 19/06/2019 Updated: 16/10/2020
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.1 | Impact Score: 5.2 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:P

Vulnerability Summary

It exists that PHP incorrectly handled certain exif tags in images. A remote attacker could use this issue to cause PHP to crash, resulting in a denial of service, or possibly obtain sensitive information. (CVE-2019-11036)

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

php php

redhat software collections 1.0

opensuse leap 15.0

opensuse leap 15.1

debian debian linux 9.0

debian debian linux 10.0

Vendor Advisories

Several security issues were fixed in PHP ...
Several security issues were fixed in PHP ...
Synopsis Moderate: php:72 security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An update for the php:72 module is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability ...
Synopsis Moderate: rh-php71-php security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An update for rh-php71-php is now available for Red Hat Software CollectionsRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerabilit ...
Synopsis Moderate: php:73 security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An update for the php:73 module is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability ...
Synopsis Critical: rh-php72-php security update Type/Severity Security Advisory: Critical Topic An update for rh-php72-php is now available for Red Hat Software CollectionsRed Hat Product Security has rated this update as having a security impact of Critical A Common Vulnerability Scoring System (CVSS) ba ...
Multiple security issues were found in PHP, a widely-used open source general purpose scripting language: Missing sanitising in the EXIF extension and the iconv_mime_decode_headers() function could result in information disclosure or denial of service For the oldstable distribution (stretch), these problems have been fixed in version 7033-0+deb9 ...
Multiple security issues were found in PHP, a widely-used open source general purpose scripting language: Missing sanitising in the EXIF extension and the iconv_mime_decode_headers() function could result in information disclosure or denial of service For the stable distribution (buster), these problems have been fixed in version 739-1~deb10u1 ...
Function iconv_mime_decode_headers() in PHP may perform out-of-buffer read due to integer overflow when parsing MIME headers This may lead to information disclosure or crash(CVE-2019-11039) When using gdImageCreateFromXbm() function of PHP gd extension, it is possible to supply data that will cause the function to use the value of uninitialized v ...
Impact: Moderate Public Date: 2019-06-18 CWE: CWE-190->CWE-125 Bugzilla: 1724152: CVE-2019-11039 php ...