Closed
Description
CVE-2019-11043 references github.com/neex/phuip-fpizdam, which may be a Go module.
Description:
In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.
References:
- NIST: https://nvd.nist.gov/vuln/detail/CVE-2019-11043
- web: https://github.com/neex/phuip-fpizdam
- web: https://bugs.php.net/bug.php?id=78599
- web: https://usn.ubuntu.com/4166-1/
- web: https://www.debian.org/security/2019/dsa-4552
- web: https://www.debian.org/security/2019/dsa-4553
- web: https://usn.ubuntu.com/4166-2/
- web: https://support.f5.com/csp/article/K75408500?utm_source=f5support&utm_medium=RSS
- web: https://lists.fedoraproject.org/archives/list/[email protected]/message/T62LF4ZWVV7OMMIZFO6IFO5QLZKK7YRD/
- web: https://security.netapp.com/advisory/ntap-20191031-0003/
- web: https://access.redhat.com/errata/RHSA-2019:3286
- web: https://access.redhat.com/errata/RHSA-2019:3287
- web: https://access.redhat.com/errata/RHSA-2019:3299
- web: https://access.redhat.com/errata/RHSA-2019:3300
- web: https://lists.fedoraproject.org/archives/list/[email protected]/message/3W23TP6X4H7LB645FYZLUPNIRD5W3EPU/
- web: https://lists.fedoraproject.org/archives/list/[email protected]/message/FSNBUSPKMLUHHOADROKNG5GDWDCRHT5M/
- web: http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00011.html
- web: https://access.redhat.com/errata/RHSA-2019:3724
- web: https://access.redhat.com/errata/RHSA-2019:3735
- web: https://access.redhat.com/errata/RHSA-2019:3736
- web: https://www.synology.com/security/advisory/Synology_SA_19_36
- web: http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00014.html
- web: https://support.apple.com/kb/HT210919
- web: https://seclists.org/bugtraq/2020/Jan/44
- web: http://seclists.org/fulldisclosure/2020/Jan/40
- web: https://access.redhat.com/errata/RHSA-2020:0322
- web: http://packetstormsecurity.com/files/156642/PHP-FPM-7.x-Remote-Code-Execution.html
- web: https://www.tenable.com/security/tns-2021-14
- Imported by: https://pkg.go.dev/github.com/neex/phuip-fpizdam?tab=importedby
Cross references:
No existing reports found with this module or alias.
See doc/triage.md for instructions on how to triage this report.
modules:
- module: github.com/neex/phuip-fpizdam
vulnerable_at: 0.0.0-20191112185237-86bc456bd5d5
packages:
- package: PHP
cves:
- CVE-2019-11043
credits:
- 'Reported by Emil Lerner. '
references:
- web: https://github.com/neex/phuip-fpizdam
- web: https://bugs.php.net/bug.php?id=78599
- web: https://usn.ubuntu.com/4166-1/
- web: https://www.debian.org/security/2019/dsa-4552
- web: https://www.debian.org/security/2019/dsa-4553
- web: https://usn.ubuntu.com/4166-2/
- web: https://support.f5.com/csp/article/K75408500?utm_source=f5support&utm_medium=RSS
- web: https://lists.fedoraproject.org/archives/list/[email protected]/message/T62LF4ZWVV7OMMIZFO6IFO5QLZKK7YRD/
- web: https://security.netapp.com/advisory/ntap-20191031-0003/
- web: https://access.redhat.com/errata/RHSA-2019:3286
- web: https://access.redhat.com/errata/RHSA-2019:3287
- web: https://access.redhat.com/errata/RHSA-2019:3299
- web: https://access.redhat.com/errata/RHSA-2019:3300
- web: https://lists.fedoraproject.org/archives/list/[email protected]/message/3W23TP6X4H7LB645FYZLUPNIRD5W3EPU/
- web: https://lists.fedoraproject.org/archives/list/[email protected]/message/FSNBUSPKMLUHHOADROKNG5GDWDCRHT5M/
- web: http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00011.html
- web: https://access.redhat.com/errata/RHSA-2019:3724
- web: https://access.redhat.com/errata/RHSA-2019:3735
- web: https://access.redhat.com/errata/RHSA-2019:3736
- web: https://www.synology.com/security/advisory/Synology_SA_19_36
- web: http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00014.html
- web: https://support.apple.com/kb/HT210919
- web: https://seclists.org/bugtraq/2020/Jan/44
- web: http://seclists.org/fulldisclosure/2020/Jan/40
- web: https://access.redhat.com/errata/RHSA-2020:0322
- web: http://packetstormsecurity.com/files/156642/PHP-FPM-7.x-Remote-Code-Execution.html
- web: https://www.tenable.com/security/tns-2021-14