2019-04-09 16:00:49 +00:00
{
"CVE_data_meta" : {
2019-05-02 22:09:52 -07:00
"ASSIGNER" : "security@php.net" ,
"DATE_PUBLIC" : "2019-04-30T14:06:00.000Z" ,
2019-04-09 16:00:49 +00:00
"ID" : "CVE-2019-11036" ,
2019-05-02 22:09:52 -07:00
"STATE" : "PUBLIC" ,
"TITLE" : "Heap over-read in PHP EXIF extension"
2019-04-09 16:00:49 +00:00
} ,
2019-05-02 22:09:52 -07:00
"affects" : {
"vendor" : {
"vendor_data" : [
{
"product" : {
"product_data" : [
{
"product_name" : "PHP" ,
"version" : {
"version_data" : [
{
"version_affected" : "<" ,
"version_name" : "7.1.x" ,
"version_value" : "7.1.29"
} ,
{
"version_affected" : "<" ,
"version_name" : "7.2.x" ,
"version_value" : "7.2.18"
} ,
{
"version_affected" : "<" ,
"version_name" : "7.3.x" ,
"version_value" : "7.3.5"
}
]
}
}
]
} ,
"vendor_name" : "PHP Group"
}
]
}
} ,
"credit" : [
{
"lang" : "eng" ,
"value" : "Discovered by OSS-fuzz in https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=14050"
}
] ,
"data_format" : "MITRE" ,
"data_type" : "CVE" ,
"data_version" : "4.0" ,
2019-04-09 16:00:49 +00:00
"description" : {
"description_data" : [
{
"lang" : "eng" ,
2019-05-03 20:00:49 +00:00
"value" : "When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.29, 7.2.x below 7.2.18 and 7.3.x below 7.3.5 can be caused to read past allocated buffer in exif_process_IFD_TAG function. This may lead to information disclosure or crash."
2019-05-02 22:09:52 -07:00
}
]
} ,
"generator" : {
"engine" : "Vulnogram 0.0.6"
} ,
"impact" : {
"cvss" : {
"attackComplexity" : "HIGH" ,
"attackVector" : "NETWORK" ,
"availabilityImpact" : "LOW" ,
"baseScore" : 4.8 ,
"baseSeverity" : "MEDIUM" ,
"confidentialityImpact" : "LOW" ,
"integrityImpact" : "NONE" ,
"privilegesRequired" : "NONE" ,
"scope" : "UNCHANGED" ,
"userInteraction" : "NONE" ,
"vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L" ,
"version" : "3.0"
}
} ,
"problemtype" : {
"problemtype_data" : [
{
"description" : [
{
"lang" : "eng" ,
"value" : "CWE-126 Buffer Over-read"
}
]
2019-04-09 16:00:49 +00:00
}
]
2019-05-02 22:09:52 -07:00
} ,
"references" : {
"reference_data" : [
{
2019-05-03 20:00:49 +00:00
"refsource" : "MISC" ,
"url" : "https://bugs.php.net/bug.php?id=77950" ,
"name" : "https://bugs.php.net/bug.php?id=77950"
2019-05-07 15:00:47 +00:00
} ,
{
"refsource" : "BID" ,
"name" : "108177" ,
"url" : "http://www.securityfocus.com/bid/108177"
2019-05-11 04:00:46 +00:00
} ,
{
"refsource" : "FEDORA" ,
"name" : "FEDORA-2019-6350c4e21a" ,
"url" : "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3BY2XUUAN277LS7HKAOGL4DVGAELOJV3/"
} ,
{
"refsource" : "FEDORA" ,
"name" : "FEDORA-2019-6e325234a4" ,
"url" : "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2NFXYNCXZCPYT7ZN4ZLI5EPQQW44FRRO/"
2019-05-12 01:01:29 +00:00
} ,
{
"refsource" : "FEDORA" ,
"name" : "FEDORA-2019-bab3944fee" ,
"url" : "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WN2HLPGEZEF4MFM5YC5FILZB5QEQFP3A/"
2019-05-17 10:00:43 +00:00
} ,
{
"refsource" : "CONFIRM" ,
"name" : "https://security.netapp.com/advisory/ntap-20190517-0003/" ,
"url" : "https://security.netapp.com/advisory/ntap-20190517-0003/"
2019-05-22 16:00:45 +00:00
} ,
{
"refsource" : "UBUNTU" ,
"name" : "USN-3566-2" ,
"url" : "https://usn.ubuntu.com/3566-2/"
2019-05-25 13:00:48 +00:00
} ,
{
"refsource" : "MLIST" ,
"name" : "[debian-lts-announce] 20190525 [SECURITY] [DLA 1803-1] php5 security update" ,
"url" : "https://lists.debian.org/debian-lts-announce/2019/05/msg00035.html"
2019-06-03 15:00:51 +00:00
} ,
{
"refsource" : "SUSE" ,
"name" : "openSUSE-SU-2019:1501" ,
"url" : "http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00010.html"
} ,
{
"refsource" : "SUSE" ,
"name" : "openSUSE-SU-2019:1503" ,
"url" : "http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00012.html"
2019-06-05 18:00:49 +00:00
} ,
{
"refsource" : "UBUNTU" ,
"name" : "USN-4009-1" ,
"url" : "https://usn.ubuntu.com/4009-1/"
2019-06-18 18:00:47 +00:00
} ,
{
"refsource" : "SUSE" ,
"name" : "openSUSE-SU-2019:1572" ,
"url" : "http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00041.html"
2019-06-18 19:00:47 +00:00
} ,
{
"refsource" : "SUSE" ,
"name" : "openSUSE-SU-2019:1573" ,
"url" : "http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00044.html"
2019-08-19 11:00:47 +00:00
} ,
{
"refsource" : "REDHAT" ,
"name" : "RHSA-2019:2519" ,
"url" : "https://access.redhat.com/errata/RHSA-2019:2519"
2019-09-20 10:00:53 +00:00
} ,
{
"refsource" : "BUGTRAQ" ,
"name" : "20190920 [SECURITY] [DSA 4527-1] php7.3 security update" ,
"url" : "https://seclists.org/bugtraq/2019/Sep/35"
2019-09-20 11:01:00 +00:00
} ,
{
"refsource" : "DEBIAN" ,
"name" : "DSA-4527" ,
"url" : "https://www.debian.org/security/2019/dsa-4527"
2019-09-23 11:00:53 +00:00
} ,
{
"refsource" : "DEBIAN" ,
"name" : "DSA-4529" ,
"url" : "https://www.debian.org/security/2019/dsa-4529"
} ,
{
"refsource" : "BUGTRAQ" ,
"name" : "20190923 [SECURITY] [DSA 4529-1] php7.0 security update" ,
"url" : "https://seclists.org/bugtraq/2019/Sep/38"
2019-11-01 16:01:16 +00:00
} ,
{
"refsource" : "REDHAT" ,
"name" : "RHSA-2019:3299" ,
"url" : "https://access.redhat.com/errata/RHSA-2019:3299"
2019-05-02 22:09:52 -07:00
}
]
} ,
"source" : {
"defect" : [
"https://bugs.php.net/bug.php?id=77950"
] ,
"discovery" : "INTERNAL"
2019-04-09 16:00:49 +00:00
}
}