Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-11048

Опубликовано: 20 мая 2020
Источник: debian
EPSS Средний

Описание

In PHP versions 7.2.x below 7.2.31, 7.3.x below 7.3.18 and 7.4.x below 7.4.6, when HTTP file uploads are allowed, supplying overly long filenames or field names could lead PHP engine to try to allocate oversized memory storage, hit the memory limit and stop processing the request, without cleaning up temporary files created by upload request. This potentially could lead to accumulation of uncleaned temporary files exhausting the disk space on the target server.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
php7.4fixed7.4.9-1package
php7.3removedpackage
php7.0removedpackage
php5removedpackage

Примечания

  • Fixed in PHP 7.2.31, 7.3.18, 7.4.6

  • PHP Bug: https://bugs.php.net/78875

  • PHP Bug: https://bugs.php.net/78876

  • https://github.com/php/php-src/commit/f43041250f82ed69bd4575655984fbfc842da266

  • https://github.com/php/php-src/commit/1c9bd513ac5c7c1d13d7f0dfa7c16a7ad2ce0f87

  • php-7.4: https://github.com/php/php-src/commit/a3924ab6542a358a3099de992b63b932a9570add

  • php-7.3: https://github.com/php/php-src/commit/f43041250f82ed69bd4575655984fbfc842da266

  • php-7.2: https://github.com/php/php-src/commit/f43041250f82ed69bd4575655984fbfc842da266

  • php-7.2: https://github.com/php/php-src/commit/1c9bd513ac5c7c1d13d7f0dfa7c16a7ad2ce0f87

EPSS

Процентиль: 95%
0.21786
Средний

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 5 лет назад

In PHP versions 7.2.x below 7.2.31, 7.3.x below 7.3.18 and 7.4.x below 7.4.6, when HTTP file uploads are allowed, supplying overly long filenames or field names could lead PHP engine to try to allocate oversized memory storage, hit the memory limit and stop processing the request, without cleaning up temporary files created by upload request. This potentially could lead to accumulation of uncleaned temporary files exhausting the disk space on the target server.

CVSS3: 7.5
redhat
около 5 лет назад

In PHP versions 7.2.x below 7.2.31, 7.3.x below 7.3.18 and 7.4.x below 7.4.6, when HTTP file uploads are allowed, supplying overly long filenames or field names could lead PHP engine to try to allocate oversized memory storage, hit the memory limit and stop processing the request, without cleaning up temporary files created by upload request. This potentially could lead to accumulation of uncleaned temporary files exhausting the disk space on the target server.

CVSS3: 5.3
nvd
около 5 лет назад

In PHP versions 7.2.x below 7.2.31, 7.3.x below 7.3.18 and 7.4.x below 7.4.6, when HTTP file uploads are allowed, supplying overly long filenames or field names could lead PHP engine to try to allocate oversized memory storage, hit the memory limit and stop processing the request, without cleaning up temporary files created by upload request. This potentially could lead to accumulation of uncleaned temporary files exhausting the disk space on the target server.

suse-cvrf
почти 5 лет назад

Security update for php7

suse-cvrf
почти 5 лет назад

Security update for php7

EPSS

Процентиль: 95%
0.21786
Средний