SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-11045

This could lead to security vulnerabilities, e.g. in applications checking paths that the code is allowed to access.

MEDIUM 5.9EPSS 8.82%

Does this matter?

Lower severity and a low EPSS score (8.82%). Track it; it rarely justifies an emergency change on its own.

Description

In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP DirectoryIterator class accepts filenames with embedded \0 byte and treats them as terminating at that byte. This could lead to security vulnerabilities, e.g. in applications checking paths that the code is allowed to access.

CVSS 3.1
5.9 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
8.82% probability · 95th percentile
CISA KEV
Not listed
Weakness
CWE-170, CWE-74
Affected
php/php · fedoraproject/fedora · debian/debian linux · opensuse/leap · canonical/ubuntu linux · tenable/security center
Source
security@php.net

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.