CVE-2019-11048
Last modified
CVE-2019-11048 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. In PHP versions 7.2.x below 7.2.31, 7.3.x below 7.3.18 and 7.4.x below 7.4.6, when HTTP file uploads are allowed, supplying overly long filenames or field names could lead PHP engine to try to allocate oversized memory storage, hit the memory limit and stop processing the request, without cleaning up temporary files created by upload request. This potentially could lead to accumulation of uncleaned temporary files exhausting the disk space on the target server.. EPSS estimates a 6.26% chance of exploitation in the next 30 days.
Description
In PHP versions 7.2.x below 7.2.31, 7.3.x below 7.3.18 and 7.4.x below 7.4.6, when HTTP file uploads are allowed, supplying overly long filenames or field names could lead PHP engine to try to allocate oversized memory storage, hit the memory limit and stop processing the request, without cleaning up temporary files created by upload request. This potentially could lead to accumulation of uncleaned temporary files exhausting the disk space on the target server.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Php | Php | >= 7.2.0, < 7.2.31 |
| Php | Php | >= 7.3.0, < 7.3.18 |
| Php | Php | >= 7.4.0, < 7.4.6 |
References
- https://bugs.php.net/bug.php?id=78875Exploit, Issue Tracking, Vendor Advisory
- https://bugs.php.net/bug.php?id=78876Exploit, Issue Tracking, Vendor Advisory
- https://bugs.php.net/bug.php?id=78875Exploit, Issue Tracking, Vendor Advisory
- https://bugs.php.net/bug.php?id=78876Exploit, Issue Tracking, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-11048?
How severe is CVE-2019-11048?
How do I fix CVE-2019-11048?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-11042When PHP EXIF extension is parsing EXIF information from an …7.1
- CVE-2019-11043In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7…9.8
- CVE-2019-11044In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7…7.5
- CVE-2019-11045In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7…5.9
- CVE-2019-11046In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7…5.3
- CVE-2019-11047When PHP EXIF extension is parsing EXIF information from an …6.5
- CVE-2019-11049In PHP versions 7.3.x below 7.3.13 and 7.4.0 on Windows, whe…9.8
- CVE-2019-1105A spoofing vulnerability exists in the way Microsoft Outlook…
- CVE-2019-11050When PHP EXIF extension is parsing EXIF information from an …6.5
- CVE-2019-11057SQL injection vulnerability in Vtiger CRM before 7.1.0 hotfi…8.8
- CVE-2019-11059Das U-Boot 2016.11-rc1 through 2019.04 mishandles the ext4 6…
- CVE-2019-1106A remote code execution vulnerability exists in the way that…
Are you affected by CVE-2019-11048?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
