In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP bcmath extension functions on some systems, including Windows, can be tricked into reading beyond the allocated space by supplying it with string containing characters that are identified as numeric by the OS but aren't ASCII numbers. This can read to disclosure of the content of some memory locations.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2050-1 | php5 security update |
Debian DSA |
DSA-4626-1 | php7.3 security update |
Debian DSA |
DSA-4628-1 | php7.0 security update |
EUVD |
EUVD-2019-2754 | In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP bcmath extension functions on some systems, including Windows, can be tricked into reading beyond the allocated space by supplying it with string containing characters that are identified as numeric by the OS but aren't ASCII numbers. This can read to disclosure of the content of some memory locations. |
Ubuntu USN |
USN-4239-1 | PHP vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: php
Published:
Updated: 2024-09-16T17:52:45.661Z
Reserved: 2019-04-09T00:00:00
Link: CVE-2019-11046
No data.
Status : Modified
Published: 2019-12-23T03:15:11.710
Modified: 2024-11-21T04:20:26.563
Link: CVE-2019-11046
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN