CVE-2019-11048

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

In PHP versions 7.2.x below 7.2.31, 7.3.x below 7.3.18 and 7.4.x below 7.4.6, when HTTP file uploads are allowed, supplying overly long filenames or field names could lead PHP engine to try to allocate oversized memory storage, hit the memory limit and stop processing the request, without cleaning up temporary files created by upload request. This potentially could lead to accumulation of uncleaned temporary files exhausting the disk space on the target server.

References

https://bugs.php.net/bug.php?id=78876

https://bugs.php.net/bug.php?id=78875

https://lists.fedoraproject.org/archives/list/[email protected]/message/OBA3TFZSP3TB5N4G24SO6BI64RJZXE3D/

https://lists.fedoraproject.org/archives/list/[email protected]/message/XMDUQ7XFONY3BWTAQQUD3QUGZT6NFZUF/

https://security.netapp.com/advisory/ntap-20200528-0006/

https://usn.ubuntu.com/4375-1/

http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00045.html

https://lists.debian.org/debian-lts-announce/2020/06/msg00033.html

https://www.debian.org/security/2020/dsa-4717

https://www.debian.org/security/2020/dsa-4719

https://www.oracle.com/security-alerts/cpuoct2020.html

https://www.oracle.com/security-alerts/cpuApr2021.html

Details

Source: MITRE

Published: 2020-05-20

Updated: 2021-07-22

Type: CWE-190

Risk Information

CVSS v2

Base Score: 5

Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Impact Score: 2.9

Exploitability Score: 10

Severity: MEDIUM

CVSS v3

Base Score: 5.3

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Impact Score: 1.4

Exploitability Score: 3.9

Severity: MEDIUM

Tenable Plugins

View all (26 total)

IDNameProductFamilySeverity
152986Tenable SecurityCenter < 5.19.0 Multiple Vulnerabilities (TNS-2021-14)NessusMisc.
high
151985Tenable.sc < 5.19.0 Multiple Vulnerabilities (TNS-2021-14) (deprecated)NessusMisc.
high
145957CentOS 8 : php:7.3 (CESA-2020:3662)NessusCentOS Local Security Checks
critical
142352EulerOS 2.0 SP2 : php (EulerOS-SA-2020-2384)NessusHuawei Local Security Checks
critical
140834EulerOS 2.0 SP3 : php (EulerOS-SA-2020-2067)NessusHuawei Local Security Checks
critical
140482Oracle Linux 8 : php:7.3 (ELSA-2020-3662)NessusOracle Linux Local Security Checks
critical
140396RHEL 8 : php:7.3 (RHSA-2020:3662)NessusRed Hat Local Security Checks
critical
139998EulerOS Virtualization for ARM 64 3.0.6.0 : php (EulerOS-SA-2020-1895)NessusHuawei Local Security Checks
high
139151EulerOS 2.0 SP8 : php (EulerOS-SA-2020-1821)NessusHuawei Local Security Checks
high
138695openSUSE Security Update : php7 (openSUSE-2020-847)NessusSuSE Local Security Checks
medium
138639Amazon Linux AMI : php72 / php73 (ALAS-2020-1397)NessusAmazon Linux Local Security Checks
medium
138289SUSE SLES12 Security Update : php5 (SUSE-SU-2020:1714-1)NessusSuSE Local Security Checks
medium
138270SUSE SLED15 / SLES15 Security Update : php7 (SUSE-SU-2020:1661-2)NessusSuSE Local Security Checks
medium
138269SUSE SLES15 Security Update : php7 (SUSE-SU-2020:1661-1)NessusSuSE Local Security Checks
medium
138225Debian DSA-4719-1 : php7.3 - security updateNessusDebian Local Security Checks
high
138106Debian DSA-4717-1 : php7.0 - security updateNessusDebian Local Security Checks
medium
137886Debian DLA-2261-1 : php5 security updateNessusDebian Local Security Checks
medium
112492PHP 7.2.x < 7.2.31 Denial of Service VulnerabilityWeb Application ScanningComponent Vulnerability
medium
112489PHP 7.3.x < 7.3.18 Denial of Service VulnerabilityWeb Application ScanningComponent Vulnerability
medium
112488PHP 7.4.x < 7.4.6 Denial of Service VulnerabilityWeb Application ScanningComponent Vulnerability
medium
137588SUSE SLES12 Security Update : php72 (SUSE-SU-2020:1546-1)NessusSuSE Local Security Checks
medium
137587SUSE SLES12 Security Update : php7 (SUSE-SU-2020:1545-1)NessusSuSE Local Security Checks
medium
136944Ubuntu 16.04 LTS / 18.04 LTS / 19.10 / 20.04 : PHP vulnerability (USN-4375-1)NessusUbuntu Local Security Checks
medium
136780Fedora 30 : php (2020-9fa7f4e25c)NessusFedora Local Security Checks
medium
136779Fedora 31 : php (2020-8838d072d5)NessusFedora Local Security Checks
medium
136741PHP 7.2.x < 7.2.31 / 7.3.x < 7.3.18, 7.4.x < 7.4.6 Denial of Service (DoS)NessusCGI abuses
medium