CVE-2019-11043
קריטית 9.8 מנוצלת בשטח (KEV) בשימוש בכופרה
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- PHP FastCGI Process Manager (FPM) Buffer Overflow Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 99% (אחוזון 100) נכון ל-4/8/2026
- CWE
- CWE-120, CWE-787
מוצרים מושפעים
php: php; canonical: ubuntu linux; debian: debian linux; fedoraproject: fedora; tenable: tenable.sc; redhat: software collections; redhat: enterprise linux; redhat: enterprise linux desktop; redhat: enterprise linux eus; redhat: enterprise linux eus compute node; redhat: enterprise linux for arm 64; redhat: enterprise linux for arm 64 eus; redhat: enterprise linux for ibm z systems; redhat: enterprise linux for ibm z systems eus; redhat: enterprise linux for power big endian
קישורים
- https://bugs.php.net/bug.php?id=78599 ExploitIssue TrackingPatchVendor Advisory
- https://bugs.php.net/bug.php?id=78599 ExploitIssue TrackingPatchVendor Advisory
- http://packetstormsecurity.com/files/156642/PHP-FPM-7.x-Remote-Code-Execution.… ExploitThird Party AdvisoryVDB Entry
- https://github.com/neex/phuip-fpizdam ExploitThird Party Advisory
- http://packetstormsecurity.com/files/156642/PHP-FPM-7.x-Remote-Code-Execution.… ExploitThird Party AdvisoryVDB Entry
- https://github.com/neex/phuip-fpizdam ExploitThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00011.html Mailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00014.html Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2020/Jan/40 Mailing ListThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3286 Third Party Advisory