CyberSec.Space Logo
CVEブラウザに戻る

CVE-2019-11043

Known Exploited (CISA KEV)HIGH
8.7
CVSS Severity Score
EPSS Score36.5090%
EPSS Percentile91.43th
Published2019年10月28日
Last Modified2025年11月3日

Vulnerability Description

In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.

Affected Platforms (CPE)

📦
Php

Php

>= 7.1.0 and < 7.1.33
📦
Php

Php

>= 7.2.0 and < 7.2.24
📦
Php

Php

>= 7.3.0 and < 7.3.11
💻
Canonical

Ubuntu Linux

= 12.04
💻
Canonical

Ubuntu Linux

= 14.04
💻
Canonical

Ubuntu Linux

= 16.04
💻
Canonical

Ubuntu Linux

= 18.04
💻
Canonical

Ubuntu Linux

= 19.04
💻
Canonical

Ubuntu Linux

= 19.10
💻
Debian

Debian Linux

= 9.0
💻
Debian

Debian Linux

= 10.0
💻
Fedoraproject

Fedora

= 29
💻
Fedoraproject

Fedora

= 30
💻
Fedoraproject

Fedora

= 31
📦
Tenable

Tenable.sc

< 5.19.0
📦
Redhat

Software Collections

= 1.0
💻
Redhat

Enterprise Linux

= 8.0
💻
Redhat

Enterprise Linux Desktop

= 6.0
💻
Redhat

Enterprise Linux Desktop

= 7.0
💻
Redhat

Enterprise Linux Eus

= 7.7
💻
Redhat

Enterprise Linux Eus

= 8.1
💻
Redhat

Enterprise Linux Eus

= 8.2
💻
Redhat

Enterprise Linux Eus

= 8.4
💻
Redhat

Enterprise Linux Eus

= 8.6
💻
Redhat

Enterprise Linux Eus

= 8.8
💻
Redhat

Enterprise Linux Eus Compute Node

= 7.7
💻
Redhat

Enterprise Linux For Arm 64

= 8.0_aarch64
💻
Redhat

Enterprise Linux For Arm 64 Eus

= 8.1_aarch64
💻
Redhat

Enterprise Linux For Arm 64 Eus

= 8.2_aarch64
💻
Redhat

Enterprise Linux For Arm 64 Eus

= 8.4_aarch64
💻
Redhat

Enterprise Linux For Arm 64 Eus

= 8.6_aarch64
💻
Redhat

Enterprise Linux For Arm 64 Eus

= 8.8_aarch64
💻
Redhat

Enterprise Linux For Ibm Z Systems

= 6.0_s390x
💻
Redhat

Enterprise Linux For Ibm Z Systems

= 7.0_s390x
💻
Redhat

Enterprise Linux For Ibm Z Systems

= 8.0_s390x
💻
Redhat

Enterprise Linux For Ibm Z Systems Eus

= 7.7_s390x
💻
Redhat

Enterprise Linux For Ibm Z Systems Eus

= 8.1_s390x
💻
Redhat

Enterprise Linux For Ibm Z Systems Eus

= 8.2_s390x
💻
Redhat

Enterprise Linux For Ibm Z Systems Eus

= 8.4_s390x
💻
Redhat

Enterprise Linux For Ibm Z Systems Eus

= 8.6_s390x
💻
Redhat

Enterprise Linux For Ibm Z Systems Eus

= 8.8_s390x
💻
Redhat

Enterprise Linux For Power Big Endian

= 6.0_ppc64
💻
Redhat

Enterprise Linux For Power Big Endian

= 7.0_ppc64
💻
Redhat

Enterprise Linux For Power Big Endian Eus

= 7.7_ppc64
💻
Redhat

Enterprise Linux For Power Little Endian

= 7.0_ppc64le
💻
Redhat

Enterprise Linux For Power Little Endian

= 8.0_ppc64le
💻
Redhat

Enterprise Linux For Power Little Endian Eus

= 7.7_ppc64le
💻
Redhat

Enterprise Linux For Power Little Endian Eus

= 8.1_ppc64le
💻
Redhat

Enterprise Linux For Power Little Endian Eus

= 8.2_ppc64le
💻
Redhat

Enterprise Linux For Power Little Endian Eus

= 8.4_ppc64le
💻
Redhat

Enterprise Linux For Power Little Endian Eus

= 8.6_ppc64le
💻
Redhat

Enterprise Linux For Power Little Endian Eus

= 8.8_ppc64le
💻
Redhat

Enterprise Linux For Scientific Computing

= 7.0
💻
Redhat

Enterprise Linux Server

= 6.0
💻
Redhat

Enterprise Linux Server

= 7.0
💻
Redhat

Enterprise Linux Server Aus

= 7.7
💻
Redhat

Enterprise Linux Server Aus

= 8.2
💻
Redhat

Enterprise Linux Server Aus

= 8.4
💻
Redhat

Enterprise Linux Server Aus

= 8.6
💻
Redhat

Enterprise Linux Server Tus

= 7.7
💻
Redhat

Enterprise Linux Server Tus

= 8.2
💻
Redhat

Enterprise Linux Server Tus

= 8.4
💻
Redhat

Enterprise Linux Server Tus

= 8.6
💻
Redhat

Enterprise Linux Server Tus

= 8.8
💻
Redhat

Enterprise Linux Workstation

= 6.0
💻
Redhat

Enterprise Linux Workstation

= 7.0

References & Advisories

関連する脆弱性情報