CVE-2019-11042: heap-buffer-overflow on exif_process_user_comment in EXIF extension
apachemodphp. Multiple issues were addressed by updating to PHP version 7.3.8.
Other sources
Fixed bug (heap-buffer-overflow on exifprocessusercomment). (CVE-2019-11042)
— PHP
heap-buffer-overflow on exifprocessusercomment
Upstream issue and fix:
https://bugs.php.net/bug.php?id=78256
— Red Hat
When PHP EXIF extension is parsing EXIF information from an image, e.g. via exifreaddata() function, in PHP versions 7.1.x below 7.1.31, 7.2.x below 7.2.21 and 7.3.x below 7.3.8 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.
Credit
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2019-8787
- CVE-2019-8796
- CVE-2019-8748
- CVE-2019-11041
- CVE-2019-11042
- CVE-2019-8824
- CVE-2019-8803
- CVE-2019-8817
- CVE-2019-8716
- CVE-2019-8788
- CVE-2019-8706
- CVE-2019-8785
- CVE-2019-8797
- CVE-2019-8850
- CVE-2019-8789
- CVE-2017-7152
- CVE-2019-8592
- CVE-2019-8705
- CVE-2019-8825
- CVE-2019-8736
- CVE-2019-8767
- CVE-2019-8737
- CVE-2019-8509
- CVE-2019-8798
- CVE-2019-8746
- CVE-2018-12152
- CVE-2018-12153
- CVE-2018-12154
- CVE-2019-8784
- CVE-2019-8807
- CVE-2019-8759
- CVE-2019-8801
- CVE-2019-8709
- CVE-2019-8794
- CVE-2019-8717
- CVE-2019-8786
- CVE-2019-8744
- CVE-2019-8829
- CVE-2019-8749
- CVE-2019-8756
- CVE-2019-8750
- CVE-2019-8802
- CVE-2019-8772
- CVE-2019-8708
- CVE-2019-8715
- CVE-2019-8858
- CVE-2019-8805
- CVE-2019-8754
- CVE-2019-8745
- CVE-2019-8831
- CVE-2019-8761
- CVE-2019-15126
- CVE-2019-8774
- CVE-2019-8753
- CVE-2019-8741
- CVE-2019-8757
- CVE-2019-8776
- CVE-2019-8758
- CVE-2019-8755
- CVE-2019-8703
- CVE-2019-8809
- CVE-2019-8781
- CVE-2019-8799
- CVE-2019-8826
- CVE-2019-8730
- CVE-2019-8855
- CVE-2019-8770
- CVE-2019-8701
- CVE-2019-8769
- CVE-2019-8768
- CVE-2019-8854
Frequently Asked Questions
What is CVE-2019-11042?
CVE-2019-11042 is a fixed bug that causes a heap-buffer-overflow vulnerability on the exif_process_user_comment function in PHP versions 7.1.x below 7.1.31, 7.2.x below 7.2.21, and 7.3.x below 7.3.8.
What is the severity of CVE-2019-11042?
The severity of CVE-2019-11042 is low with a severity value of 3.7.
How does CVE-2019-11042 affect PHP?
CVE-2019-11042 affects PHP by allowing an attacker to supply EXIF information that can cause the PHP EXIF extension to read past the allocated buffer, potentially leading to information leakage or denial of service.
Which versions of PHP are affected by CVE-2019-11042?
PHP versions 7.1.x below 7.1.31, 7.2.x below 7.2.21, and 7.3.x below 7.3.8 are affected by CVE-2019-11042.
How can I fix CVE-2019-11042?
To fix CVE-2019-11042, update PHP to version 7.1.31 or higher for PHP 7.1.x, version 7.2.21 or higher for PHP 7.2.x, or version 7.3.8 or higher for PHP 7.3.x.