Lucene search

K
f5F5F5:K44650157
HistoryJan 22, 2020 - 12:00 a.m.

K44650157 : PHP DirectoryIterator vulnerability CVE-2019-11045

2020-01-2200:00:00
my.f5.com
186

7.3 High

AI Score

Confidence

High

0.008 Low

EPSS

Percentile

81.8%

Security Advisory Description

In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP DirectoryIterator class accepts filenames with embedded \0 byte and treats them as terminating at that byte. This could lead to security vulnerabilities, e.g. in applications checking paths that the code is allowed to access. (CVE-2019-11045)

Impact

There is no impact; F5 products are not affected by this vulnerability.