6.4
CVSSv2

CVE-2019-11034

Published: 18/04/2019 Updated: 02/10/2020
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.1 | Impact Score: 5.2 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:P

Vulnerability Summary

It exists that PHP incorrectly handled certain exif tags in JPEG images. A remote attacker could use this issue to cause PHP to crash, resulting in a denial of service, or possibly execute arbitrary code.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

php php

canonical ubuntu linux 18.04

canonical ubuntu linux 18.10

canonical ubuntu linux 14.04

canonical ubuntu linux 12.04

canonical ubuntu linux 16.04

canonical ubuntu linux 19.04

netapp storage automation store -

redhat software collections 1.0

debian debian linux 8.0

debian debian linux 9.0

opensuse leap 15.0

opensuse leap 15.1

opensuse leap 42.3

Vendor Advisories

Several security issues were fixed in PHP ...
Several security issues were fixed in PHP ...
Multiple security issues were found in PHP, a widely-used open source general purpose scripting language: Missing sanitising in the EXIF extension and the iconv_mime_decode_headers() function could result in information disclosure or denial of service For the oldstable distribution (stretch), these problems have been fixed in version 7033-0+deb9 ...
Synopsis Moderate: php:72 security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An update for the php:72 module is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability ...
Synopsis Moderate: rh-php71-php security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An update for rh-php71-php is now available for Red Hat Software CollectionsRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerabilit ...
Synopsis Critical: rh-php72-php security update Type/Severity Security Advisory: Critical Topic An update for rh-php72-php is now available for Red Hat Software CollectionsRed Hat Product Security has rated this update as having a security impact of Critical A Common Vulnerability Scoring System (CVSS) ba ...
When processing certain files, PHP EXIF extension in versions 71x below 7128, 72x below 7217 and 73x below 734 can be caused to read past allocated buffer in exif_iif_add_value function This may lead to information disclosure or crash (CVE-2019-11035) When processing certain files, PHP EXIF extension in versions 71x below 7128, 7 ...

Github Repositories

Search a CVE based on a product name and version

Search CVE Search a CVE based on a product name and version Installation python3 -m venv venv source venv/bin/activate pip install -r requirementstxt Update the CVE database with the following command: python mainpy update Download db files from nvdnistgov/ downloading year 2002 to nvdcve-10-2002json downloadi