VulnerabilityModified
CVE-2019-9020
An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1.
CRITICAL 9.8EPSS 10.1%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 10.1%, higher than 95% of all known CVEs. Patch or mitigate before the next change window.
Description
An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. Invalid input to the function xmlrpc_decode() can lead to an invalid memory access (heap out of bounds read or read after free). This is related to xml_elem_parse_buf in ext/xmlrpc/libxmlrpc/xml_element.c.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 10.06% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-125, CWE-416
- Affected
- php/php · debian/debian linux · canonical/ubuntu linux · netapp/storage automation store · opensuse/leap
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00083.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00104.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00041.html
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00044.html
- http://www.securityfocus.com/bid/107156Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2019:2519
- https://access.redhat.com/errata/RHSA-2019:3299
- https://bugs.php.net/bug.php?id=77242Exploit, Issue Tracking, Patch, Vendor Advisory
- https://bugs.php.net/bug.php?id=77249Exploit, Issue Tracking, Vendor Advisory
- https://security.netapp.com/advisory/ntap-20190321-0001/Third Party Advisory
- https://usn.ubuntu.com/3902-1/Third Party Advisory
- https://usn.ubuntu.com/3902-2/Third Party Advisory
- https://www.debian.org/security/2019/dsa-4398Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00083.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00104.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00041.html
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00044.html
- http://www.securityfocus.com/bid/107156Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2019:2519
- https://access.redhat.com/errata/RHSA-2019:3299
- https://bugs.php.net/bug.php?id=77242Exploit, Issue Tracking, Patch, Vendor Advisory
- https://bugs.php.net/bug.php?id=77249Exploit, Issue Tracking, Vendor Advisory
- https://security.netapp.com/advisory/ntap-20190321-0001/Third Party Advisory
- https://usn.ubuntu.com/3902-1/Third Party Advisory
- https://usn.ubuntu.com/3902-2/Third Party Advisory
- https://www.debian.org/security/2019/dsa-4398Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.