First published: Wed Jan 15 2020(Updated: )
It was discovered that PHP incorrectly handled certain files. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 14.04 ESM, 16.04 LTS, 18.04 LTS, 19.04 and 19.10. (CVE-2019-11045) It was discovered that PHP incorrectly handled certain inputs. An attacker could possibly use this issue to expose sensitive information. (CVE-2019-11046) It was discovered that PHP incorrectly handled certain images. An attacker could possibly use this issue to access sensitive information. (CVE-2019-11047, CVE-2019-11050)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libapache2-mod-php7.3 | <7.3.11-0ubuntu0.19.10.2 | 7.3.11-0ubuntu0.19.10.2 |
Ubuntu Linux | =19.10 | |
All of | ||
ubuntu/php7.3-bcmath | <7.3.11-0ubuntu0.19.10.2 | 7.3.11-0ubuntu0.19.10.2 |
Ubuntu Linux | =19.10 | |
All of | ||
ubuntu/php7.3-cgi | <7.3.11-0ubuntu0.19.10.2 | 7.3.11-0ubuntu0.19.10.2 |
Ubuntu Linux | =19.10 | |
All of | ||
ubuntu/php7.3-cli | <7.3.11-0ubuntu0.19.10.2 | 7.3.11-0ubuntu0.19.10.2 |
Ubuntu Linux | =19.10 | |
All of | ||
ubuntu/php7.3-fpm | <7.3.11-0ubuntu0.19.10.2 | 7.3.11-0ubuntu0.19.10.2 |
Ubuntu Linux | =19.10 | |
All of | ||
ubuntu/php7.3-mbstring | <7.3.11-0ubuntu0.19.10.2 | 7.3.11-0ubuntu0.19.10.2 |
Ubuntu Linux | =19.10 | |
All of | ||
ubuntu/php7.3-xmlrpc | <7.3.11-0ubuntu0.19.10.2 | 7.3.11-0ubuntu0.19.10.2 |
Ubuntu Linux | =19.10 | |
All of | ||
ubuntu/libapache2-mod-php7.2 | <7.2.24-0ubuntu0.19.04.2 | 7.2.24-0ubuntu0.19.04.2 |
Ubuntu Linux | =19.04 | |
All of | ||
ubuntu/php7.2-bcmath | <7.2.24-0ubuntu0.19.04.2 | 7.2.24-0ubuntu0.19.04.2 |
Ubuntu Linux | =19.04 | |
All of | ||
ubuntu/php7.2-cgi | <7.2.24-0ubuntu0.19.04.2 | 7.2.24-0ubuntu0.19.04.2 |
Ubuntu Linux | =19.04 | |
All of | ||
ubuntu/php7.2-cli | <7.2.24-0ubuntu0.19.04.2 | 7.2.24-0ubuntu0.19.04.2 |
Ubuntu Linux | =19.04 | |
All of | ||
ubuntu/php7.2-fpm | <7.2.24-0ubuntu0.19.04.2 | 7.2.24-0ubuntu0.19.04.2 |
Ubuntu Linux | =19.04 | |
All of | ||
ubuntu/php7.2-mbstring | <7.2.24-0ubuntu0.19.04.2 | 7.2.24-0ubuntu0.19.04.2 |
Ubuntu Linux | =19.04 | |
All of | ||
ubuntu/php7.2-xmlrpc | <7.2.24-0ubuntu0.19.04.2 | 7.2.24-0ubuntu0.19.04.2 |
Ubuntu Linux | =19.04 | |
All of | ||
ubuntu/libapache2-mod-php7.2 | <7.2.24-0ubuntu0.18.04.2 | 7.2.24-0ubuntu0.18.04.2 |
Ubuntu Linux | =18.04 | |
All of | ||
ubuntu/php7.2-bcmath | <7.2.24-0ubuntu0.18.04.2 | 7.2.24-0ubuntu0.18.04.2 |
Ubuntu Linux | =18.04 | |
All of | ||
ubuntu/php7.2-cgi | <7.2.24-0ubuntu0.18.04.2 | 7.2.24-0ubuntu0.18.04.2 |
Ubuntu Linux | =18.04 | |
All of | ||
ubuntu/php7.2-cli | <7.2.24-0ubuntu0.18.04.2 | 7.2.24-0ubuntu0.18.04.2 |
Ubuntu Linux | =18.04 | |
All of | ||
ubuntu/php7.2-fpm | <7.2.24-0ubuntu0.18.04.2 | 7.2.24-0ubuntu0.18.04.2 |
Ubuntu Linux | =18.04 | |
All of | ||
ubuntu/php7.2-mbstring | <7.2.24-0ubuntu0.18.04.2 | 7.2.24-0ubuntu0.18.04.2 |
Ubuntu Linux | =18.04 | |
All of | ||
ubuntu/php7.2-xmlrpc | <7.2.24-0ubuntu0.18.04.2 | 7.2.24-0ubuntu0.18.04.2 |
Ubuntu Linux | =18.04 | |
All of | ||
ubuntu/libapache2-mod-php7.0 | <7.0.33-0ubuntu0.16.04.9 | 7.0.33-0ubuntu0.16.04.9 |
Ubuntu Linux | =16.04 | |
All of | ||
ubuntu/php7.0-bcmath | <7.0.33-0ubuntu0.16.04.9 | 7.0.33-0ubuntu0.16.04.9 |
Ubuntu Linux | =16.04 | |
All of | ||
ubuntu/php7.0-cgi | <7.0.33-0ubuntu0.16.04.9 | 7.0.33-0ubuntu0.16.04.9 |
Ubuntu Linux | =16.04 | |
All of | ||
ubuntu/php7.0-cli | <7.0.33-0ubuntu0.16.04.9 | 7.0.33-0ubuntu0.16.04.9 |
Ubuntu Linux | =16.04 | |
All of | ||
ubuntu/php7.0-fpm | <7.0.33-0ubuntu0.16.04.9 | 7.0.33-0ubuntu0.16.04.9 |
Ubuntu Linux | =16.04 | |
All of | ||
ubuntu/php7.0-mbstring | <7.0.33-0ubuntu0.16.04.9 | 7.0.33-0ubuntu0.16.04.9 |
Ubuntu Linux | =16.04 | |
All of | ||
ubuntu/php7.0-xmlrpc | <7.0.33-0ubuntu0.16.04.9 | 7.0.33-0ubuntu0.16.04.9 |
Ubuntu Linux | =16.04 | |
All of | ||
ubuntu/libapache2-mod-php5 | <5.5.9+dfsg-1ubuntu4.29+esm8 | 5.5.9+dfsg-1ubuntu4.29+esm8 |
Ubuntu Linux | =14.04 | |
All of | ||
ubuntu/php5-cgi | <5.5.9+dfsg-1ubuntu4.29+esm8 | 5.5.9+dfsg-1ubuntu4.29+esm8 |
Ubuntu Linux | =14.04 | |
All of | ||
ubuntu/php5-cli | <5.5.9+dfsg-1ubuntu4.29+esm8 | 5.5.9+dfsg-1ubuntu4.29+esm8 |
Ubuntu Linux | =14.04 | |
All of | ||
ubuntu/php5-fpm | <5.5.9+dfsg-1ubuntu4.29+esm8 | 5.5.9+dfsg-1ubuntu4.29+esm8 |
Ubuntu Linux | =14.04 | |
All of | ||
ubuntu/php5-xmlrpc | <5.5.9+dfsg-1ubuntu4.29+esm8 | 5.5.9+dfsg-1ubuntu4.29+esm8 |
Ubuntu Linux | =14.04 | |
All of | ||
ubuntu/libapache2-mod-php5 | <5.3.10-1ubuntu3.42 | 5.3.10-1ubuntu3.42 |
Ubuntu Linux | =12.04 | |
All of | ||
ubuntu/php5-cgi | <5.3.10-1ubuntu3.42 | 5.3.10-1ubuntu3.42 |
Ubuntu Linux | =12.04 | |
All of | ||
ubuntu/php5-cli | <5.3.10-1ubuntu3.42 | 5.3.10-1ubuntu3.42 |
Ubuntu Linux | =12.04 | |
All of | ||
ubuntu/php5-fpm | <5.3.10-1ubuntu3.42 | 5.3.10-1ubuntu3.42 |
Ubuntu Linux | =12.04 | |
All of | ||
ubuntu/php5-xmlrpc | <5.3.10-1ubuntu3.42 | 5.3.10-1ubuntu3.42 |
Ubuntu Linux | =12.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Contains the following vulnerabilities)
The vulnerability USN-4239-1 has high severity due to its potential to cause denial of service.
To fix USN-4239-1, update PHP packages to the versions provided in the advisory.
USN-4239-1 affects Ubuntu 14.04 ESM, 16.04 LTS, 18.04 LTS, 19.04, and 19.10.
CVE-2019-11045 relates to improper handling of certain files in PHP, which can lead to denial of service attacks.
Yes, the recommended version to upgrade to is 7.3.11-0ubuntu0.19.10.2 or equivalent for the affected versions.