First published: Sat Mar 16 2019(Updated: )
Fixed bug (Heap-buffer-overflow in php_ifd_get32s). (CVE-2019-11034)
Credit: security@php.net security@php.net
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/rh-php71-php | <0:7.1.30-1.el7 | 0:7.1.30-1.el7 |
redhat/rh-php72-php | <0:7.2.24-1.el7 | 0:7.2.24-1.el7 |
PHP PHP | >=7.1.0<7.1.28 | |
PHP PHP | >=7.2.9<7.2.17 | |
PHP PHP | >=7.3.0<7.3.4 | |
Canonical Ubuntu Linux | =12.04 | |
Canonical Ubuntu Linux | =14.04 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =18.04 | |
Canonical Ubuntu Linux | =18.10 | |
Canonical Ubuntu Linux | =19.04 | |
Netapp Storage Automation Store | ||
Redhat Software Collections | =1.0 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 | |
openSUSE Leap | =15.0 | |
openSUSE Leap | =15.1 | |
openSUSE Leap | =42.3 | |
PHP PHP | <7.1.28 | 7.1.28 |
redhat/php | <7.1.28 | 7.1.28 |
redhat/php | <7.2.17 | 7.2.17 |
redhat/php | <7.3.4 | 7.3.4 |
debian/php5 | ||
debian/php7.0 | ||
debian/php7.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2019-11034 is a fixed bug in the PHP EXIF extension that can cause a heap-buffer-overflow vulnerability.
The severity of CVE-2019-11034 is medium, with a CVSS score of 6.5.
CVE-2019-11034 can lead to information disclosure or crash when processing certain files in PHP versions 7.1.x, 7.2.x, and 7.3.x.
PHP versions 7.1.x below 7.1.28, 7.2.x below 7.2.17, and 7.3.x below 7.3.4 are affected by CVE-2019-11034.
To fix CVE-2019-11034, update your PHP installation to version 7.1.28, 7.2.17, or 7.3.4.