Vulnerability Details CVE-2019-11043
In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.941
EPSS Ranking 99.9%
CVSS Severity
CVSS v3 Score 8.7
CVSS v2 Score 7.5
Proposed Action
In some versions of PHP in certain configurations of FPM setup, it is possible to cause FPM module to write past allocated buffers allowing the possibility of remote code execution.
Ransomware Campaign
Known
Products affected by CVE-2019-11043
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
cpe:2.3:a:redhat:software_collections:1.0
-
cpe:2.3:a:tenable:tenable.sc:-
-
cpe:2.3:a:tenable:tenable.sc:5.13.0
-
cpe:2.3:a:tenable:tenable.sc:5.14.0
-
cpe:2.3:a:tenable:tenable.sc:5.14.1
-
cpe:2.3:a:tenable:tenable.sc:5.16.0
-
cpe:2.3:a:tenable:tenable.sc:5.17.0
-
cpe:2.3:a:tenable:tenable.sc:5.18.0
-
cpe:2.3:o:canonical:ubuntu_linux:12.04
-
cpe:2.3:o:canonical:ubuntu_linux:14.04
-
cpe:2.3:o:canonical:ubuntu_linux:16.04
-
cpe:2.3:o:canonical:ubuntu_linux:18.04
-
cpe:2.3:o:canonical:ubuntu_linux:19.04
-
cpe:2.3:o:canonical:ubuntu_linux:19.10
-
cpe:2.3:o:debian:debian_linux:10.0
-
cpe:2.3:o:debian:debian_linux:9.0
-
cpe:2.3:o:fedoraproject:fedora:29
-
cpe:2.3:o:fedoraproject:fedora:30
-
cpe:2.3:o:fedoraproject:fedora:31
-
cpe:2.3:o:redhat:enterprise_linux:8.0
-
cpe:2.3:o:redhat:enterprise_linux_desktop:6.0
-
cpe:2.3:o:redhat:enterprise_linux_desktop:7.0
-
cpe:2.3:o:redhat:enterprise_linux_eus:7.7
-
cpe:2.3:o:redhat:enterprise_linux_eus:8.1
-
cpe:2.3:o:redhat:enterprise_linux_eus:8.2
-
cpe:2.3:o:redhat:enterprise_linux_eus:8.4
-
cpe:2.3:o:redhat:enterprise_linux_eus:8.6
-
cpe:2.3:o:redhat:enterprise_linux_eus:8.8
-
cpe:2.3:o:redhat:enterprise_linux_eus_compute_node:7.7
-
cpe:2.3:o:redhat:enterprise_linux_for_arm_64:8.0_aarch64
-
cpe:2.3:o:redhat:enterprise_linux_for_arm_64_eus:8.1_aarch64
-
cpe:2.3:o:redhat:enterprise_linux_for_arm_64_eus:8.2_aarch64
-
cpe:2.3:o:redhat:enterprise_linux_for_arm_64_eus:8.4_aarch64
-
cpe:2.3:o:redhat:enterprise_linux_for_arm_64_eus:8.6_aarch64
-
cpe:2.3:o:redhat:enterprise_linux_for_arm_64_eus:8.8_aarch64
-
cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:6.0_s390x
-
cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:7.0_s390x
-
cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:8.0_s390x
-
cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:7.7_s390x
-
cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:8.1_s390x
-
cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:8.2_s390x
-
cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:8.4_s390x
-
cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:8.6_s390x
-
cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:8.8_s390x
-
cpe:2.3:o:redhat:enterprise_linux_for_power_big_endian:6.0_ppc64
-
cpe:2.3:o:redhat:enterprise_linux_for_power_big_endian:7.0_ppc64
-
cpe:2.3:o:redhat:enterprise_linux_for_power_big_endian_eus:7.7_ppc64
-
cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:7.0_ppc64le
-
cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:8.0_ppc64le
-
cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:7.7_ppc64le
-
cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.1_ppc64le
-
cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.2_ppc64le
-
cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.4_ppc64le
-
cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.6_ppc64le
-
cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.8_ppc64le
-
cpe:2.3:o:redhat:enterprise_linux_for_scientific_computing:7.0
-
cpe:2.3:o:redhat:enterprise_linux_server:6.0
-
cpe:2.3:o:redhat:enterprise_linux_server:7.0
-
cpe:2.3:o:redhat:enterprise_linux_server_aus:7.7
-
cpe:2.3:o:redhat:enterprise_linux_server_aus:8.2
-
cpe:2.3:o:redhat:enterprise_linux_server_aus:8.4
-
cpe:2.3:o:redhat:enterprise_linux_server_aus:8.6
-
cpe:2.3:o:redhat:enterprise_linux_server_tus:7.7
-
cpe:2.3:o:redhat:enterprise_linux_server_tus:8.2
-
cpe:2.3:o:redhat:enterprise_linux_server_tus:8.4
-
cpe:2.3:o:redhat:enterprise_linux_server_tus:8.6
-
cpe:2.3:o:redhat:enterprise_linux_server_tus:8.8
-
cpe:2.3:o:redhat:enterprise_linux_workstation:6.0
-
cpe:2.3:o:redhat:enterprise_linux_workstation:7.0