Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2019-11043
Description:In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.
Test IDs: 1.3.6.1.4.1.25623.1.0.883128   1.3.6.1.4.1.25623.1.1.12.2019.4166.2   1.3.6.1.4.1.25623.1.0.170132   1.3.6.1.4.1.25623.1.1.2.2019.2295   1.3.6.1.4.1.25623.1.0.108692   1.3.6.1.4.1.25623.1.0.891970   1.3.6.1.4.1.25623.1.0.704552   1.3.6.1.4.1.25623.1.0.844212   1.3.6.1.4.1.25623.1.1.4.2019.2819.1   1.3.6.1.4.1.25623.1.0.170133   1.3.6.1.4.1.25623.1.0.877110   1.3.6.1.4.1.25623.1.1.10.2019.0307   1.3.6.1.4.1.25623.1.0.852763   1.3.6.1.4.1.25623.1.0.704553   1.3.6.1.4.1.25623.1.0.876962   1.3.6.1.4.1.25623.1.1.4.2019.2909.1   1.3.6.1.4.1.25623.1.1.4.2019.2809.1   1.3.6.1.4.1.25623.1.0.170131   1.3.6.1.4.1.25623.1.0.852842   1.3.6.1.4.1.25623.1.0.883127  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2019-11043
Bugtraq: 20200129 APPLE-SA-2020-1-28-2 macOS Catalina 10.15.3, Security Update 2020-001 Mojave, Security Update 2020-001 High Sierra (Google Search)
https://seclists.org/bugtraq/2020/Jan/44
Debian Security Information: DSA-4552 (Google Search)
https://www.debian.org/security/2019/dsa-4552
Debian Security Information: DSA-4553 (Google Search)
https://www.debian.org/security/2019/dsa-4553
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3W23TP6X4H7LB645FYZLUPNIRD5W3EPU/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T62LF4ZWVV7OMMIZFO6IFO5QLZKK7YRD/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FSNBUSPKMLUHHOADROKNG5GDWDCRHT5M/
http://seclists.org/fulldisclosure/2020/Jan/40
http://packetstormsecurity.com/files/156642/PHP-FPM-7.x-Remote-Code-Execution.html
https://github.com/neex/phuip-fpizdam
RedHat Security Advisories: RHSA-2019:3286
https://access.redhat.com/errata/RHSA-2019:3286
RedHat Security Advisories: RHSA-2019:3287
https://access.redhat.com/errata/RHSA-2019:3287
RedHat Security Advisories: RHSA-2019:3299
https://access.redhat.com/errata/RHSA-2019:3299
RedHat Security Advisories: RHSA-2019:3300
https://access.redhat.com/errata/RHSA-2019:3300
RedHat Security Advisories: RHSA-2019:3724
https://access.redhat.com/errata/RHSA-2019:3724
RedHat Security Advisories: RHSA-2019:3735
https://access.redhat.com/errata/RHSA-2019:3735
RedHat Security Advisories: RHSA-2019:3736
https://access.redhat.com/errata/RHSA-2019:3736
RedHat Security Advisories: RHSA-2020:0322
https://access.redhat.com/errata/RHSA-2020:0322
SuSE Security Announcement: openSUSE-SU-2019:2441 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00011.html
SuSE Security Announcement: openSUSE-SU-2019:2457 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00014.html
https://usn.ubuntu.com/4166-1/
https://usn.ubuntu.com/4166-2/




© 1998-2025 E-Soft Inc. All rights reserved.