SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-11044

This could lead to security vulnerabilities, e.g. in applications checking paths that the code is allowed to access.

HIGH 7.5EPSS 5.12%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (5.12%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 on Windows, PHP link() function accepts filenames with embedded \0 byte and treats them as terminating at that byte. This could lead to security vulnerabilities, e.g. in applications checking paths that the code is allowed to access.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
5.12% probability · 92th percentile
CISA KEV
Not listed
Weakness
CWE-170
Affected
php/php · tenable/security center · fedoraproject/fedora
Source
security@php.net

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.