ZeroHour

CVE-2019-11045

PoC
CVSS 3.1
5.9 medium
EPSS
9%p95
Published
()
Modified
Description

In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP DirectoryIterator class accepts filenames with embedded \0 byte and treats them as terminating at that byte. This could lead to security vulnerabilities, e.g. in applications checking paths that the code is allowed to access.

Vendors
phpfedoraprojectdebianopensusecanonicaltenable
Products
php, fedora, debian linux, leap, ubuntu linux, security center
Weakness
CWE-170, CWE-74
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.