First published: Sat Mar 16 2019(Updated: )
Fixed bug (Heap-buffer-overflow in php_ifd_get32s). (CVE-2019-11034)
Credit: security@php.net
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/rh-php71-php | <0:7.1.30-1.el7 | 0:7.1.30-1.el7 |
redhat/rh-php72-php | <0:7.2.24-1.el7 | 0:7.2.24-1.el7 |
redhat/php | <7.1.28 | 7.1.28 |
redhat/php | <7.2.17 | 7.2.17 |
redhat/php | <7.3.4 | 7.3.4 |
debian/php5 | ||
debian/php7.0 | ||
debian/php7.3 | ||
PHP | <7.1.28 | 7.1.28 |
PHP | >=7.1.0<7.1.28 | |
PHP | >=7.2.9<7.2.17 | |
PHP | >=7.3.0<7.3.4 | |
Ubuntu | =12.04 | |
Ubuntu | =14.04 | |
Ubuntu | =16.04 | |
Ubuntu | =18.04 | |
Ubuntu | =18.10 | |
Ubuntu | =19.04 | |
NetApp Storage Automation Store | ||
Red Hat Software Collections | =1.0 | |
Debian | =8.0 | |
Debian | =9.0 | |
SUSE Linux | =15.0 | |
SUSE Linux | =15.1 | |
SUSE Linux | =42.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2019-11034 is a fixed bug in the PHP EXIF extension that can cause a heap-buffer-overflow vulnerability.
The severity of CVE-2019-11034 is medium, with a CVSS score of 6.5.
CVE-2019-11034 can lead to information disclosure or crash when processing certain files in PHP versions 7.1.x, 7.2.x, and 7.3.x.
PHP versions 7.1.x below 7.1.28, 7.2.x below 7.2.17, and 7.3.x below 7.3.4 are affected by CVE-2019-11034.
To fix CVE-2019-11034, update your PHP installation to version 7.1.28, 7.2.17, or 7.3.4.