CVE-2019-11044
גבוהה 7.5
תיאור (מקור, אנגלית)
In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 on Windows, PHP link() function accepts filenames with embedded \0 byte and treats them as terminating at that byte. This could lead to security vulnerabilities, e.g. in applications checking paths that the code is allowed to access.
מדדים
- CVSS 3.1
-
7.5 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - EPSS — סבירות ניצול
- 5% (אחוזון 100) נכון ל-19/8/2026
- CWE
- CWE-170
מוצרים מושפעים
php: php; tenable: security center; fedoraproject: fedora
קישורים
- https://bugs.php.net/bug.php?id=78862 ExploitMailing ListPatchVendor Advisory
- https://bugs.php.net/bug.php?id=78862 ExploitMailing ListPatchVendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorap…
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorap…
- https://security.netapp.com/advisory/ntap-20200103-0002/ Third Party Advisory
- https://www.tenable.com/security/tns-2021-14 Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorap…
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorap…
- https://security.netapp.com/advisory/ntap-20200103-0002/ Third Party Advisory
- https://www.tenable.com/security/tns-2021-14 Third Party Advisory