Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1970-1 | php5 security update |
Debian DSA |
DSA-4552-1 | php7.0 security update |
Debian DSA |
DSA-4553-1 | php7.3 security update |
Ubuntu USN |
USN-4166-1 | PHP vulnerability |
Ubuntu USN |
USN-4166-2 | PHP vulnerability |
Solution
No solution given by the vendor.
Workaround
Configuring nginx (or other server that implements the front-end part of the FPM protocol) to check for the existence of the target file before passing it to PHP FPM (e.g. "try_files $uri =404" or "if (-f $uri)" in nginx) for would prevent this vulnerability from happening.
Wed, 22 Oct 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 21 Oct 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 21 Oct 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 07 Feb 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
kev
|
Wed, 14 Aug 2024 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Status: PUBLISHED
Assigner: php
Published:
Updated: 2025-10-21T23:45:28.408Z
Reserved: 2019-04-09T00:00:00.000Z
Link: CVE-2019-11043
Updated: 2024-08-04T22:40:16.064Z
Status : Analyzed
Published: 2019-10-28T15:15:13.863
Modified: 2025-11-03T19:23:46.417
Link: CVE-2019-11043
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
Ubuntu USN