Updated: 2025-11-10 01:03:42.447797
Description:
In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.
| Links | NIST | CIRCL | RHEL | Ubuntu |
| Severity | Score | |
|---|---|---|
| CVSS Version 2.x | HIGH | 7.5 |
| CVSS Version 3.x | CRITICAL | 9.8 |
| Added Date | Description | Due Date | Notes |
|---|---|---|---|
| 2022-03-25 | In some versions of PHP in certain configurations of FPM setup, it is possible to cause FPM module to write past allocated buffers allowing the possibility of remote code execution. | 2022-04-15 | https://nvd.nist.gov/vuln/detail/CVE-2019-11043 |
| OS name | Project name | Version | Score | Severity | Status | Errata | Last updated | Statement |
|---|---|---|---|---|---|---|---|---|
| Debian 10 | php | 8.0 | 9.8 | CRITICAL | Not Vulnerable | 2025-06-04 05:55:12 | ||
| Debian 10 | php | 5.6 | 9.8 | CRITICAL | Released | CLSA-2025:1751048186 | 2025-06-28 02:53:03 | |
| Debian 10 | php | 7.3 | 9.8 | CRITICAL | Not Vulnerable | 2025-06-04 05:55:13 | ||
| Debian 10 | php | 8.2 | 9.8 | CRITICAL | Not Vulnerable | 2025-06-04 05:55:12 | ||
| Debian 10 | php | 8.1 | 9.8 | CRITICAL | Not Vulnerable | 2025-06-04 05:55:12 | ||
| Debian 10 | php | 7.0 | 9.8 | CRITICAL | Released | CLSA-2025:1751098944 | 2025-06-29 04:17:49 | |
| Debian 10 | php | 7.1 | 9.8 | CRITICAL | Not Vulnerable | 2025-06-04 05:55:13 | ||
| Debian 10 | php | 7.2 | 9.8 | CRITICAL | Not Vulnerable | 2025-06-04 05:55:13 | ||
| Debian 10 | php | 7.4 | 9.8 | CRITICAL | Not Vulnerable | 2025-06-04 05:55:12 | ||
| Debian 11 | php | 8.1 | 9.8 | CRITICAL | Not Vulnerable | 2025-06-04 05:55:11 |