CVE-2019-11045

Published Dec 23, 2019

Last updated 21 days ago

Overview

Description
In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP DirectoryIterator class accepts filenames with embedded \0 byte and treats them as terminating at that byte. This could lead to security vulnerabilities, e.g. in applications checking paths that the code is allowed to access.
Source
security@php.net
NVD status
Modified
Products
php, fedora, debian_linux, leap, ubuntu_linux, security_center

Risk scores

CVSS 3.1

Type
Primary
Base score
5.9
Impact score
3.6
Exploitability score
2.2
Vector string
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity
MEDIUM

CVSS 2.0

Type
Primary
Base score
4.3
Impact score
2.9
Exploitability score
8.6
Vector string
AV:N/AC:M/Au:N/C:P/I:N/A:N

Weaknesses

security@php.net
CWE-170
nvd@nist.gov
CWE-74

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.