CVE-2019-11040: Heap buffer overflow in EXIF extension
Fixed bug (heap-buffer-overflow on phpjpgget16) (CVE-2019-11040).
Other sources
When PHP EXIF extension is parsing EXIF information from an image, e.g ...
— Debian
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/rh-php71-phpto a version that resolves this vulnerability.Fixed in 0:7.1.30-1.el7 - Upgrade
Upgrade
redhat/rh-php72-phpto a version that resolves this vulnerability.Fixed in 0:7.2.24-1.el7 - Upgrade
Upgrade
redhat/phpto a version that resolves this vulnerability.Fixed in 7.1.30 - Upgrade
Upgrade
redhat/phpto a version that resolves this vulnerability.Fixed in 7.2.19 - Upgrade
Upgrade
redhat/phpto a version that resolves this vulnerability.Fixed in 7.3.6 - Upgrade
Upgrade
PHPto a version that resolves this vulnerability.Fixed in 7.1.30 - Upgrade
Upgrade
PHP EXIF extensionto a version that resolves this vulnerability.Fixed in 7.1.30 - Upgrade
Upgrade
PHP EXIF extensionto a version that resolves this vulnerability.Fixed in 7.2.19 - Upgrade
Upgrade
PHP EXIF extensionto a version that resolves this vulnerability.Fixed in 7.3.6 - Compensating control
If upgrading is not immediately possible, avoid processing untrusted images with the PHP EXIF extension (e.g., avoid calling exif_read_data() on attacker-supplied images) to reduce risk of information disclosure or crashes.
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2019-11040?
CVE-2019-11040 is a vulnerability in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19, and 7.3.x below 7.3.6 that can cause a heap buffer overflow when parsing EXIF information from an image.
How severe is CVE-2019-11040?
CVE-2019-11040 has a severity rating of 6.5 (medium).
How can I check if I am affected by CVE-2019-11040?
You are affected by CVE-2019-11040 if you are using PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19, or 7.3.x below 7.3.6.
How do I fix CVE-2019-11040?
To fix CVE-2019-11040, you need to update PHP to version 7.1.30, 7.2.19, or 7.3.6.
Where can I find more information about CVE-2019-11040?
You can find more information about CVE-2019-11040 in the PHP ChangeLog, CVE database, NVD database, and Red Hat Bugzilla.