CyberSec.Space Logo
Back to CVE Browser

CVE-2019-11043

Known Exploited (CISA KEV)HIGH
8.7
CVSS Severity Score
EPSS Score36.5090%
EPSS Percentile91.43th
PublishedOct 28, 2019
Last ModifiedNov 3, 2025

Vulnerability Description

In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.

Affected Platforms (CPE)

πŸ“¦
Php

Php

>= 7.1.0 and < 7.1.33
πŸ“¦
Php

Php

>= 7.2.0 and < 7.2.24
πŸ“¦
Php

Php

>= 7.3.0 and < 7.3.11
πŸ’»
Canonical

Ubuntu Linux

= 12.04
πŸ’»
Canonical

Ubuntu Linux

= 14.04
πŸ’»
Canonical

Ubuntu Linux

= 16.04
πŸ’»
Canonical

Ubuntu Linux

= 18.04
πŸ’»
Canonical

Ubuntu Linux

= 19.04
πŸ’»
Canonical

Ubuntu Linux

= 19.10
πŸ’»
Debian

Debian Linux

= 9.0
πŸ’»
Debian

Debian Linux

= 10.0
πŸ’»
Fedoraproject

Fedora

= 29
πŸ’»
Fedoraproject

Fedora

= 30
πŸ’»
Fedoraproject

Fedora

= 31
πŸ“¦
Tenable

Tenable.sc

< 5.19.0
πŸ“¦
Redhat

Software Collections

= 1.0
πŸ’»
Redhat

Enterprise Linux

= 8.0
πŸ’»
Redhat

Enterprise Linux Desktop

= 6.0
πŸ’»
Redhat

Enterprise Linux Desktop

= 7.0
πŸ’»
Redhat

Enterprise Linux Eus

= 7.7
πŸ’»
Redhat

Enterprise Linux Eus

= 8.1
πŸ’»
Redhat

Enterprise Linux Eus

= 8.2
πŸ’»
Redhat

Enterprise Linux Eus

= 8.4
πŸ’»
Redhat

Enterprise Linux Eus

= 8.6
πŸ’»
Redhat

Enterprise Linux Eus

= 8.8
πŸ’»
Redhat

Enterprise Linux Eus Compute Node

= 7.7
πŸ’»
Redhat

Enterprise Linux For Arm 64

= 8.0_aarch64
πŸ’»
Redhat

Enterprise Linux For Arm 64 Eus

= 8.1_aarch64
πŸ’»
Redhat

Enterprise Linux For Arm 64 Eus

= 8.2_aarch64
πŸ’»
Redhat

Enterprise Linux For Arm 64 Eus

= 8.4_aarch64
πŸ’»
Redhat

Enterprise Linux For Arm 64 Eus

= 8.6_aarch64
πŸ’»
Redhat

Enterprise Linux For Arm 64 Eus

= 8.8_aarch64
πŸ’»
Redhat

Enterprise Linux For Ibm Z Systems

= 6.0_s390x
πŸ’»
Redhat

Enterprise Linux For Ibm Z Systems

= 7.0_s390x
πŸ’»
Redhat

Enterprise Linux For Ibm Z Systems

= 8.0_s390x
πŸ’»
Redhat

Enterprise Linux For Ibm Z Systems Eus

= 7.7_s390x
πŸ’»
Redhat

Enterprise Linux For Ibm Z Systems Eus

= 8.1_s390x
πŸ’»
Redhat

Enterprise Linux For Ibm Z Systems Eus

= 8.2_s390x
πŸ’»
Redhat

Enterprise Linux For Ibm Z Systems Eus

= 8.4_s390x
πŸ’»
Redhat

Enterprise Linux For Ibm Z Systems Eus

= 8.6_s390x
πŸ’»
Redhat

Enterprise Linux For Ibm Z Systems Eus

= 8.8_s390x
πŸ’»
Redhat

Enterprise Linux For Power Big Endian

= 6.0_ppc64
πŸ’»
Redhat

Enterprise Linux For Power Big Endian

= 7.0_ppc64
πŸ’»
Redhat

Enterprise Linux For Power Big Endian Eus

= 7.7_ppc64
πŸ’»
Redhat

Enterprise Linux For Power Little Endian

= 7.0_ppc64le
πŸ’»
Redhat

Enterprise Linux For Power Little Endian

= 8.0_ppc64le
πŸ’»
Redhat

Enterprise Linux For Power Little Endian Eus

= 7.7_ppc64le
πŸ’»
Redhat

Enterprise Linux For Power Little Endian Eus

= 8.1_ppc64le
πŸ’»
Redhat

Enterprise Linux For Power Little Endian Eus

= 8.2_ppc64le
πŸ’»
Redhat

Enterprise Linux For Power Little Endian Eus

= 8.4_ppc64le
πŸ’»
Redhat

Enterprise Linux For Power Little Endian Eus

= 8.6_ppc64le
πŸ’»
Redhat

Enterprise Linux For Power Little Endian Eus

= 8.8_ppc64le
πŸ’»
Redhat

Enterprise Linux For Scientific Computing

= 7.0
πŸ’»
Redhat

Enterprise Linux Server

= 6.0
πŸ’»
Redhat

Enterprise Linux Server

= 7.0
πŸ’»
Redhat

Enterprise Linux Server Aus

= 7.7
πŸ’»
Redhat

Enterprise Linux Server Aus

= 8.2
πŸ’»
Redhat

Enterprise Linux Server Aus

= 8.4
πŸ’»
Redhat

Enterprise Linux Server Aus

= 8.6
πŸ’»
Redhat

Enterprise Linux Server Tus

= 7.7
πŸ’»
Redhat

Enterprise Linux Server Tus

= 8.2
πŸ’»
Redhat

Enterprise Linux Server Tus

= 8.4
πŸ’»
Redhat

Enterprise Linux Server Tus

= 8.6
πŸ’»
Redhat

Enterprise Linux Server Tus

= 8.8
πŸ’»
Redhat

Enterprise Linux Workstation

= 6.0
πŸ’»
Redhat

Enterprise Linux Workstation

= 7.0

References & Advisories

Related Vulnerabilities