VulnerabilityModified
CVE-2019-11044
This could lead to security vulnerabilities, e.g. in applications checking paths that the code is allowed to access.
HIGH 7.5EPSS 5.12%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.12%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 on Windows, PHP link() function accepts filenames with embedded \0 byte and treats them as terminating at that byte. This could lead to security vulnerabilities, e.g. in applications checking paths that the code is allowed to access.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 5.12% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-170
- Affected
- php/php · tenable/security center · fedoraproject/fedora
- Source
- security@php.net
References
- https://bugs.php.net/bug.php?id=78862Exploit, Mailing List, Patch, Vendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N7GCOAE6KVHYJ3UQ4KLPLTGSLX6IRVRN/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XWRQPYXVG43Q7DXMXH6UVWMKWGUW552F/
- https://security.netapp.com/advisory/ntap-20200103-0002/Third Party Advisory
- https://www.tenable.com/security/tns-2021-14Third Party Advisory
- https://bugs.php.net/bug.php?id=78862Exploit, Mailing List, Patch, Vendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N7GCOAE6KVHYJ3UQ4KLPLTGSLX6IRVRN/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XWRQPYXVG43Q7DXMXH6UVWMKWGUW552F/
- https://security.netapp.com/advisory/ntap-20200103-0002/Third Party Advisory
- https://www.tenable.com/security/tns-2021-14Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.