In PHP versions 7.3.x below 7.3.15 and 7.4.x below 7.4.3, while extracting PHAR files on Windows using phar extension, certain content inside PHAR file could lead to one-byte read past the allocated buffer. This could potentially lead to information disclosure or crash.
A flaw was found in php before 7.4.2. An out of bounds read in phpstriptagsex may lead to denial of service or potentially disclosure of sensitive data.
Upstream issue:
https://bugs.php.net/79099
A flaw was found in php before 7.4.2. A global buffer overflow in mbflfiltconvbig5wchar function may lead to corruption of memory data.
Upstream issue:
http://bugs.php.net/79037
Fixed bug (mail() may release string with refcount==1 twice). (CVE-2019-11049)
apachemodphp. Multiple issues were addressed by updating to PHP version 7.3.11.
A use-after-free in onignewdeluxe() in regext.c in Oniguruma 6.9.2 allows attackers to potentially cause information disclosure, denial of service, or possibly code execution by providing a crafted regular expression. The attacker provides a pair of a regex pattern and a string, with a multi-byte encoding that gets handled by onignewdeluxe(). Oniguruma issues often affect Ruby, as well as common optional libraries for PHP and Rust.
Fixed bug (Out-of-bounds read in iconv.c:phpiconvmimedecode() due to integer overflow) (CVE-2019-11039).
Fixed bug (heap-buffer-overflow on phpjpgget16) (CVE-2019-11040).
Fixed bug (Heap-buffer-overflow in estrndup via exifprocessIFDTAG) (CVE-2019-11036).
Fixed bug (Heap-buffer-overflow in exifiifaddvalue). (CVE-2019-11035)
Fixed bug (Heap-buffer-overflow in phpifdget32s). (CVE-2019-11034)
An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in exifprocessIFDinTIFF.
An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. A number of heap-based buffer over-read instances are present in mbstring regular expression functions when supplied with invalid multibyte data. These occur in ext/mbstring/oniguruma/regcomp.c, ext/mbstring/oniguruma/regexec.c, ext/mbstring/oniguruma/regparse.c, ext/mbstring/oniguruma/enc/unicode.c, and ext/mbstring/oniguruma/src/utf32be.c when a multibyte regular expression pattern contains invalid multibyte sequences.
An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. A heap-based buffer over-read in PHAR reading functions in the PHAR extension may allow an attacker to read allocated or unallocated memory past the actual data when trying to parse the file name, a different vulnerability than CVE-2018-20783. This is related to phardetectpharfnameext in ext/phar/phar.c.
An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. Invalid input to the function xmlrpcdecode() can lead to an invalid memory access (heap out of bounds read or read after free). This is related to xmlelemparsebuf in ext/xmlrpc/libxmlrpc/xmlelement.c.