Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2019-11045
Description:In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP DirectoryIterator class accepts filenames with embedded \0 byte and treats them as terminating at that byte. This could lead to security vulnerabilities, e.g. in applications checking paths that the code is allowed to access.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2019-11045
Bugtraq: 20200218 [SECURITY] [DSA 4626-1] php7.3 security update (Google Search)
https://seclists.org/bugtraq/2020/Feb/27
Bugtraq: 20200219 [SECURITY] [DSA 4628-1] php7.0 security update (Google Search)
https://seclists.org/bugtraq/2020/Feb/31
Bugtraq: 20210116 Re: [SECURITY] [DSA 4628-1] php7.0 security update (Google Search)
https://seclists.org/bugtraq/2021/Jan/3
Debian Security Information: DSA-4626 (Google Search)
https://www.debian.org/security/2020/dsa-4626
Debian Security Information: DSA-4628 (Google Search)
https://www.debian.org/security/2020/dsa-4628
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/N7GCOAE6KVHYJ3UQ4KLPLTGSLX6IRVRN/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XWRQPYXVG43Q7DXMXH6UVWMKWGUW552F/
https://bugs.php.net/bug.php?id=78863
https://lists.debian.org/debian-lts-announce/2019/12/msg00034.html
SuSE Security Announcement: openSUSE-SU-2020:0080 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00036.html
https://usn.ubuntu.com/4239-1/




© 1998-2025 E-Soft Inc. All rights reserved.