CVE-2019-11048
Summary
| CVE | CVE-2019-11048 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-05-20 08:15:00 UTC |
| Updated | 2023-11-07 03:02:00 UTC |
| Description | In PHP versions 7.2.x below 7.2.31, 7.3.x below 7.3.18 and 7.4.x below 7.4.6, when HTTP file uploads are allowed, supplying overly long filenames or field names could lead PHP engine to try to allocate oversized memory storage, hit the memory limit and stop processing the request, without cleaning up temporary files created by upload request. This potentially could lead to accumulation of uncleaned temporary files exhausting the disk space on the target server. |
Risk And Classification
Problem Types: CWE-190
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] Fedora 31 Update: php-7.3.18-1.fc31 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| Debian -- Security Information -- DSA-4719-1 php7.3 | DEBIAN | www.debian.org | |
| [SECURITY] Fedora 31 Update: php-7.3.18-1.fc31 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| Oracle Critical Patch Update Advisory - October 2020 | MISC | www.oracle.com | |
| [R1] Tenable.sc 5.19.0 Fixes Multiple Third-party Vulnerabilities - Security Advisory | Tenable® | CONFIRM | www.tenable.com | |
| [SECURITY] Fedora 30 Update: php-7.3.18-1.fc30 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| USN-4375-1: PHP vulnerability | Ubuntu security notices | Ubuntu | UBUNTU | usn.ubuntu.com | |
| [SECURITY] Fedora 30 Update: php-7.3.18-1.fc30 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| PHP :: Sec Bug #78875 :: Long filenames cause OOM and temp files are not cleaned | MISC | bugs.php.net | Exploit, Issue Tracking, Vendor Advisory |
| CVE-2019-11048 PHP Vulnerability in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | |
| Debian -- Security Information -- DSA-4717-1 php7.0 | DEBIAN | www.debian.org | |
| [SECURITY] [DLA 2261-1] php5 security update | MLIST | lists.debian.org | |
| PHP :: Sec Bug #78876 :: Long variables in multipart/form-data cause OOM and temp files are not cleaned | MISC | bugs.php.net | Exploit, Issue Tracking, Vendor Advisory |
| [security-announce] openSUSE-SU-2020:0847-1: moderate: Security update f | SUSE | lists.opensuse.org | |
| Oracle Critical Patch Update Advisory - April 2021 | MISC | www.oracle.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: jr at coredu dot mp
Legacy QID Mappings
- 296072 Oracle Solaris 11.4 Support Repository Update (SRU) 25.75.3 Missing (CPUJUL2020)
- 501139 Alpine Linux Security Update for php7
- 752878 SUSE Enterprise Linux Security Update for php7 (SUSE-SU-2022:4067-1)
- 940250 AlmaLinux Security Update for php:7.3 (ALSA-2020:3662)
- 960421 Rocky Linux Security Update for php:7.3 (RLSA-2020:3662)