Lucene search

K
ubuntucveUbuntu.comUB:CVE-2019-11050
HistoryDec 23, 2019 - 12:00 a.m.

CVE-2019-11050

2019-12-2300:00:00
ubuntu.com
ubuntu.com
31

6.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:N/A:P

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L

0.004 Low

EPSS

Percentile

74.4%

When PHP EXIF extension is parsing EXIF information from an image, e.g. via
exif_read_data() function, in PHP versions 7.2.x below 7.2.26, 7.3.x below
7.3.13 and 7.4.0 it is possible to supply it with data what will cause it
to read past the allocated buffer. This may lead to information disclosure
or crash.

Bugs

OSVersionArchitecturePackageVersionFilename
ubuntu14.04noarchphp5< 5.5.9+dfsg-1ubuntu4.29+esm8UNKNOWN
ubuntu16.04noarchphp7.0< 7.0.33-0ubuntu0.16.04.9UNKNOWN
ubuntu18.04noarchphp7.2< 7.2.24-0ubuntu0.18.04.2UNKNOWN
ubuntu19.04noarchphp7.2< 7.2.24-0ubuntu0.19.04.2UNKNOWN
ubuntu19.10noarchphp7.3< 7.3.11-0ubuntu0.19.10.2UNKNOWN

6.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:N/A:P

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L

0.004 Low

EPSS

Percentile

74.4%