CyberSec.Space Logo
Back to CVE Browser

CVE-2019-9020

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.0010%
EPSS Percentile7.48th
PublishedFeb 22, 2019
Last ModifiedNov 21, 2024

Vulnerability Description

An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. Invalid input to the function xmlrpc_decode() can lead to an invalid memory access (heap out of bounds read or read after free). This is related to xml_elem_parse_buf in ext/xmlrpc/libxmlrpc/xml_element.c.

Affected Platforms (CPE)

πŸ“¦
Php

Php

< 5.6.40
πŸ“¦
Php

Php

>= 7.0.0 and < 7.1.26
πŸ“¦
Php

Php

>= 7.2.0 and < 7.2.14
πŸ“¦
Php

Php

>= 7.3.0 and < 7.3.1
πŸ’»
Debian

Debian Linux

= 9.0
πŸ’»
Canonical

Ubuntu Linux

= 12.04
πŸ’»
Canonical

Ubuntu Linux

= 14.04
πŸ’»
Canonical

Ubuntu Linux

= 16.04
πŸ“¦
Netapp

Storage Automation Store

All versions
πŸ’»
Opensuse

Leap

= 42.3

References & Advisories

Related Vulnerabilities