CVE-2019-9637
Summary
| CVE | CVE-2019-9637 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-03-09 00:29:00 UTC |
| Updated | 2019-06-03 15:29:00 UTC |
| Description | An issue was discovered in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. Due to the way rename() across filesystems is implemented, it is possible that file being renamed is briefly available with wrong permissions while the rename is ongoing, thus enabling unauthorized users to access the data. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
|
| USN-3922-2: PHP vulnerabilities | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| Debian -- Security Information -- DSA-4403-1 php7.0 |
DEBIAN |
www.debian.org |
Third Party Advisory |
| [SECURITY] [DLA 1741-1] php5 security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| USN-3922-1: PHP vulnerabilities | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| PHP :: Sec Bug #77630 :: rename() across the device may allow unwanted access during processing |
MISC |
bugs.php.net |
Issue Tracking, Patch, Vendor Advisory |
| support.f5.com/csp/article/K53825211 |
CONFIRM |
support.f5.com |
Third Party Advisory |
| [security-announce] openSUSE-SU-2019:1503-1: moderate: Security update f |
SUSE |
lists.opensuse.org |
|
| [security-announce] openSUSE-SU-2019:1572-1: moderate: Security update f |
SUSE |
lists.opensuse.org |
|
| March 2019 PHP Vulnerabilities in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
Third Party Advisory |
| [R1] PHP Stand-alone Patch Available for Tenable.sc versions 5.7.x to 5.11.x - Security Advisory | Tenable® |
CONFIRM |
www.tenable.com |
|
| [security-announce] openSUSE-SU-2019:1293-1: moderate: Security update f |
SUSE |
lists.opensuse.org |
Mailing List, Third Party Advisory |
| [security-announce] openSUSE-SU-2019:1573-1: moderate: Security update f |
SUSE |
lists.opensuse.org |
|
| USN-3922-3: PHP vulnerabilities | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159670 Oracle Enterprise Linux Security Update for php:7.2 (ELSA-2020-1624)
- 296079 Oracle Solaris 11.4 Support Repository Update (SRU) 15.5.0 Missing (CPUOCT2019)
- 501127 Alpine Linux Security Update for php7
- 752878 SUSE Enterprise Linux Security Update for php7 (SUSE-SU-2022:4067-1)
- 940404 AlmaLinux Security Update for php:7.2 (ALSA-2020:1624)
- 960218 Rocky Linux Security Update for php:7.2 (RLSA-2020:1624)