In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.
Metrics
Affected Vendors & Products
References
History
Fri, 07 Feb 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
kev
|
Wed, 14 Aug 2024 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Status: PUBLISHED
Assigner: php
Published: 2019-10-28T14:19:04.252Z
Updated: 2025-07-30T01:45:55.159Z
Reserved: 2019-04-09T00:00:00.000Z
Link: CVE-2019-11043
Updated: 2024-08-04T22:40:16.064Z
Status : Analyzed
Published: 2019-10-28T15:15:13.863
Modified: 2025-02-14T16:43:36.877
Link: CVE-2019-11043