news.mlab.sh
Vulnerabilities
Vulnerability

CVE-2019-11043

Reference data from vuln.mlab.sh, coverage from our own index.

CVSS
8.7 High
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
Risk score
100.0
Known exploited
CISA KEV
Published
2019-10-28
Status
Published

In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.

Weaknesses

CWE-120

Coverage 1

Advisories and references