CVE-2019-11043
Updated: 2022-05-25 08:54:18.092603
Description:
In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.
Severity
|
Severity |
Score |
CVSS Version 2.x |
HIGH |
7.5 |
CVSS Version 3.x |
CRITICAL |
9.8 |
Known exploits
Added Date |
Description |
Due Date |
Notes |
2022-03-25 |
In some versions of PHP in certain configurations of FPM setup, it is possible to cause FPM module to write past allocated buffers allowing the possibility of remote code execution. |
2022-04-15 |
|
Status
OS name |
Project name |
Version |
Score |
Severity |
Status |
Errata |
Last updated |
EL 6 PHP |
php |
5.1 |
9.8 |
CRITICAL |
Not Vulnerable |
|
2022-08-17 11:02:15 |
EL 6 PHP |
php |
7.3 |
9.8 |
CRITICAL |
Not Vulnerable |
|
2022-08-17 11:02:15 |
EL 6 PHP |
php |
5.4 |
9.8 |
CRITICAL |
Released |
|
2022-08-17 05:02:11 |
EL 6 PHP |
php |
8.2 |
9.8 |
CRITICAL |
Not Vulnerable |
|
2023-03-22 14:02:43 |
EL 6 PHP |
php |
7.1 |
9.8 |
CRITICAL |
Not Vulnerable |
|
2022-08-17 08:02:08 |
EL 6 PHP |
php |
5.3 |
9.8 |
CRITICAL |
Released |
|
2022-08-11 17:02:16 |
EL 6 PHP |
php |
5.5 |
9.8 |
CRITICAL |
Released |
|
2022-08-17 05:02:11 |
EL 6 PHP |
php |
5.6 |
9.8 |
CRITICAL |
Released |
|
2022-08-17 05:02:11 |
EL 6 PHP |
php |
7.0 |
9.8 |
CRITICAL |
Released |
|
2022-08-17 05:02:11 |
EL 6 PHP |
php |
7.4 |
9.8 |
CRITICAL |
Not Vulnerable |
|
2022-08-17 11:02:09 |
Subscribe or unsubscribe for status updates on the latest vulnerabilities that affect your distribution.
Filter notifications by the flavor of your distro & by the availability status.