CVE-2019-11041
High
CVE-2019-11041
When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.31, 7.2.x below 7.2.21 and 7.3.x below 7.3.8 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.
Exploit probability
4.4%
Published
August 9, 2019
Required by
Not available
Last source change
August 7, 2026
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
CVE-2019-11041
View original source
When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.31, 7.2.x below 7.2.21 and 7.3.x below 7.3.8 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.
05 / REFERENCES
Further evidence
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00019.html
- http://seclists.org/fulldisclosure/2019/Oct/15
- http://seclists.org/fulldisclosure/2019/Oct/55
- https://access.redhat.com/errata/RHSA-2019:3299
- https://bugs.php.net/bug.php?id=78222
- https://lists.debian.org/debian-lts-announce/2019/08/msg00010.html
- https://seclists.org/bugtraq/2019/Oct/9
- https://seclists.org/bugtraq/2019/Sep/35
- https://seclists.org/bugtraq/2019/Sep/38
- https://security.netapp.com/advisory/ntap-20190822-0003/
- https://support.apple.com/kb/HT210634
- https://support.apple.com/kb/HT210722
- https://usn.ubuntu.com/4097-1/
- https://usn.ubuntu.com/4097-2/
- https://www.debian.org/security/2019/dsa-4527
- https://www.debian.org/security/2019/dsa-4529
- https://www.tenable.com/security/tns-2021-14