CVE-2019-9640: High severity PHP PHP vulnerability
Published Jan 29, 2019
·Updated
An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an Invalid Read in exifprocessSOFn.
Other sources
Fixed bug (Invalid Read on exifprocessSOFn). (CVE-2019-9640)
— PHP
Affected Software
24 affected componentsFixes available
redhat/rh-php71-php<0:7.1.30-1.el7
0:7.1.30-1.el7
redhat/rh-php72-php<0:7.2.24-1.el7
0:7.2.24-1.el7
redhat/php<7.1.27
7.1.27
redhat/php<7.2.16
7.2.16
redhat/php<7.3.3
7.3.3
debian/php5
debian/php7.0
debian/php7.3
PHP PHP<7.1.27
7.1.27
PHP PHP>=7.1.0<7.1.27
PHP PHP>=7.2.0<7.2.16
PHP PHP>=7.3.0<7.3.3
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=18.10
Debian Debian Linux=8.0
Debian Debian Linux=9.0
openSUSE Leap=15.0
openSUSE Leap=15.1
openSUSE Leap=42.3
NetApp Storage Automation Store
redhat Software Collections=1.0
Remediation
Patch Available
Patch Available
Event History
Jan 29, 2019
CVE Published
12:00 AM
Mar 8, 2019
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·11:33 PM
Description
Feb 23, 2026
Data Sourced
via Ubuntu·05:29 PM
RemedyDescriptionSeverityAffected Software
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
1
What is CVE-2019-9640?
CVE-2019-9640 is a vulnerability in the EXIF component in PHP before version 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3.
2
How severe is CVE-2019-9640?
CVE-2019-9640 has a severity score of 7.5 (high).
3
How does CVE-2019-9640 affect PHP?
CVE-2019-9640 allows for an Invalid Read in the EXIF component of PHP.
4
Which versions of PHP are affected by CVE-2019-9640?
PHP versions before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3 are affected by CVE-2019-9640.
5
How can I fix CVE-2019-9640?
To fix CVE-2019-9640, you should update PHP to version 7.1.27, 7.2.16, or 7.3.3.