ISOMAN

CVE

CVE-2019-11045

In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP DirectoryIterator class accepts filenames with embedded \0 byte and treats them as terminating at that byte. This could lead to security vulnerabilities, e.g. in applications checking paths that the code is allowed to access.

Severity
LOW
CVSS
3.7
Published
Modified

Linked Releases

DistributionReleaseStatusEvidence
Ubuntu18.04.6 amd64 desktopunknownsource
Ubuntu18.04.6 amd64 live-serverunknownsource

References

  1. http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00036.html
  2. https://bugs.php.net/bug.php?id=78863
  3. https://lists.debian.org/debian-lts-announce/2019/12/msg00034.html
  4. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N7GCOAE6KVHYJ3UQ4KLPLTGSLX6IRVRN/
  5. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XWRQPYXVG43Q7DXMXH6UVWMKWGUW552F/
  6. https://seclists.org/bugtraq/2020/Feb/27
  7. https://seclists.org/bugtraq/2020/Feb/31
  8. https://seclists.org/bugtraq/2021/Jan/3
  9. https://security.netapp.com/advisory/ntap-20200103-0002/
  10. https://usn.ubuntu.com/4239-1/
  11. https://www.debian.org/security/2020/dsa-4626
  12. https://www.debian.org/security/2020/dsa-4628
  13. https://www.tenable.com/security/tns-2021-14
  14. http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00036.html
  15. https://bugs.php.net/bug.php?id=78863
  16. https://lists.debian.org/debian-lts-announce/2019/12/msg00034.html
  17. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N7GCOAE6KVHYJ3UQ4KLPLTGSLX6IRVRN/
  18. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XWRQPYXVG43Q7DXMXH6UVWMKWGUW552F/
  19. https://seclists.org/bugtraq/2020/Feb/27
  20. https://seclists.org/bugtraq/2020/Feb/31