CVE-2019-11047

Updated: 2025-08-20 02:24:20.336242

Description:

When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x MEDIUM 6.4
CVSS Version 3.x MEDIUM 6.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

Debian 10 php 8.0 6.5 MEDIUM Ignored 2025-05-29 03:54:50
Debian 10 php 5.6 6.5 MEDIUM Ignored 2025-05-29 03:54:51
Debian 10 php 7.3 6.5 MEDIUM Ignored 2025-05-29 03:54:50
Debian 10 php 8.2 6.5 MEDIUM Ignored 2025-05-29 03:54:50
Debian 10 php 8.1 6.5 MEDIUM Ignored 2025-05-29 03:54:50
Debian 10 php 7.0 6.5 MEDIUM Ignored 2025-05-29 03:54:51
Debian 10 php 7.1 6.5 MEDIUM Ignored 2025-05-29 03:54:51
Debian 10 php 7.2 6.5 MEDIUM Ignored 2025-05-29 03:54:51
Debian 10 php 7.4 6.5 MEDIUM Ignored 2025-05-29 03:54:50
Debian 11 php 8.1 6.5 MEDIUM Ignored 2025-05-29 03:54:50
Total: 146