First published: Tue Dec 17 2019(Updated: )
A vulnerability was found in PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP DirectoryIterator class accepts filenames with embedded \0 byte and treats them as terminating at that byte. This could lead to security vulnerabilities, e.g. in applications checking paths that the code is allowed to access. Reference: <a href="https://bugs.php.net/bug.php?id=78863">https://bugs.php.net/bug.php?id=78863</a>
Credit: security@php.net security@php.net
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/rh-php73-php | <0:7.3.20-1.el7 | 0:7.3.20-1.el7 |
PHP PHP | >=7.2.0<=7.2.26 | |
PHP PHP | >=7.3.0<=7.3.13 | |
PHP PHP | =7.4.0 | |
Fedoraproject Fedora | =30 | |
Fedoraproject Fedora | =31 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 | |
openSUSE Leap | =15.1 | |
Canonical Ubuntu Linux | =12.04 | |
Canonical Ubuntu Linux | =14.04 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =18.04 | |
Canonical Ubuntu Linux | =19.04 | |
Canonical Ubuntu Linux | =19.10 | |
Tenable SecurityCenter | <5.19.0 | |
PHP PHP | <7.2.26 | 7.2.26 |
debian/php5 | ||
debian/php7.0 | ||
debian/php7.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2019-11045.
The severity of CVE-2019-11045 is medium with a CVSS score of 5.9.
PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13, and 7.4.0 are affected by CVE-2019-11045.
CVE-2019-11045 could lead to security vulnerabilities in applications checking paths that the code is allowed to access.
To fix CVE-2019-11045, update PHP to version 7.2.26, 7.3.13, or 7.4.1 or later.