A crafted request uri-path can cause modproxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
Fixed bug (Out-of-bounds read in iconv.c:phpiconvmimedecode() due to integer overflow) (CVE-2019-11039).
Fixed bug (heap-buffer-overflow on phpjpgget16) (CVE-2019-11040).
apachemodphp. Multiple issues were addressed by updating to PHP version 7.3.11.
Fixed bug (Heap-buffer-overflow in estrndup via exifprocessIFDTAG) (CVE-2019-11036).
A flaw was discovered where the XMLRPC client implementation in Apache XMLRPC, performed deserialization of the server-side exception serialized in the faultCause attribute of XMLRPC error response messages. A malicious or compromised XMLRPC server could possibly use this flaw to execute arbitrary code with the privileges of an application using the Apache XMLRPC client library.
Fixed bug (Heap-buffer-overflow in exifiifaddvalue). (CVE-2019-11035)
Fixed bug (Heap-buffer-overflow in phpifdget32s). (CVE-2019-11034)