CVE-2019-11034: Heap over-read in PHP EXIF extension
Fixed bug (Heap-buffer-overflow in phpifdget32s). (CVE-2019-11034)
Other sources
When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.28, 7.2.x below 7.2.17 and 7.3.x below 7.3.4 can be caused to read past allocated buffer in exifprocessIFDTAG function. This may lead to information disclosure or crash.
When processing certain files, PHP EXIF extension in versions 7.1.x below 7.2.8, 7.2.x below 7.2.17 and 7.3.x below 7.3.4 can be caused to read past allocated buffer in exifprocessIFDTAG function. This may lead to information disclosure or crash.
Reference: https://bugs.php.net/bug.php?id=77753
Upstream commit: http://git.php.net/?p=php-src.git;a=commit;h=f3aefc6d071b807ddacae0a0bc49f09c38e18490 http://git.php.net/?p=php-src.git;a=commit;h=a1631ac57b853edd81431e57c266ec813e180acd http://git.php.net/?p=php-src.git;a=commit;h=1c0d06441aefee18b30520e2b1ae89cbfcf56a59
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2019-11034?
CVE-2019-11034 is a fixed bug in the PHP EXIF extension that can cause a heap-buffer-overflow vulnerability.
What is the severity of CVE-2019-11034?
The severity of CVE-2019-11034 is medium, with a CVSS score of 6.5.
How does CVE-2019-11034 impact PHP?
CVE-2019-11034 can lead to information disclosure or crash when processing certain files in PHP versions 7.1.x, 7.2.x, and 7.3.x.
Which versions of PHP are affected by CVE-2019-11034?
PHP versions 7.1.x below 7.1.28, 7.2.x below 7.2.17, and 7.3.x below 7.3.4 are affected by CVE-2019-11034.
How can I fix CVE-2019-11034?
To fix CVE-2019-11034, update your PHP installation to version 7.1.28, 7.2.17, or 7.3.4.