PT-2020-4630 · Php+8 · Php+8

Published

2020-05-11

·

Updated

2022-11-18

·

CVE-2019-11048

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PHP versions 7.2.x through 7.2.30 PHP versions 7.3.x through 7.3.17 PHP versions 7.4.x through 7.4.5
Description The issue is related to an integer overflow buffer in the PHP language interpreter. Exploitation of this issue could allow a remote attacker to cause a denial of service. When HTTP file uploads are allowed, supplying overly long filenames or field names could lead the PHP engine to try to allocate oversized memory storage, hit the memory limit, and stop processing the request without cleaning up temporary files created by the upload request. This could potentially lead to accumulation of uncleaned temporary files, exhausting the disk space on the target server.
Recommendations For PHP versions 7.2.x through 7.2.30, update to version 7.2.31 or later to resolve the issue. For PHP versions 7.3.x through 7.3.17, update to version 7.3.18 or later to resolve the issue. For PHP versions 7.4.x through 7.4.5, update to version 7.4.6 or later to resolve the issue. As a temporary workaround, consider restricting HTTP file uploads or limiting the length of filenames and field names to prevent exploitation.

Exploit

Fix

Integer Overflow

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2020:3662
ALT-PU-2020-2057
ALT-PU-2020-2108
BDU:2020-05179
CESA-2020_3662
CVE-2019-11048
DLA-2261-1
DSA-4717-1
DSA-4719-1
MGASA-2020-0236
OPENSUSE-SU-2020:0847-1
OPENSUSE-SU-2020_0847-1
OPENSUSE-SU-2022_4067-1
RHSA-2020:3662
RHSA-2020:5275
RHSA-2020_3662
RLSA-2020:3662
SUSE-SU-2020:1545-1
SUSE-SU-2020:1546-1
SUSE-SU-2020:1661-1
SUSE-SU-2020:1661-2
SUSE-SU-2020:1714-1
SUSE-SU-2020_1545-1
SUSE-SU-2020_1546-1
SUSE-SU-2020_1661-1
SUSE-SU-2020_1661-2
SUSE-SU-2020_1714-1
SUSE-SU-2022:4067-1
USN-4375-1

Affected Products

Alt Linux
Almalinux
Centos
Linuxmint
Php
Red Hat
Rocky Linux
Suse
Ubuntu