Bug 1786570 (CVE-2019-11047)
Summary: | CVE-2019-11047 php: Information disclosure in exif_read_data() | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Dhananjay Arunesh <darunesh> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | fedora, hhorak, jorton, rcollet, webstack-team, yozone |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | php 7.2Git-2019-12-04 | Doc Type: | If docs needed, set a value |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2020-09-08 13:18:31 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1786571, 1788221, 1788222, 1788223, 1788224, 1788225, 1857703 | ||
Bug Blocks: | 1786580 |
Description
Dhananjay Arunesh
2019-12-26 09:47:42 UTC
Created php tracking bugs for this issue: Affects: fedora-all [bug 1786571] Upstream commit for this bug: http://git.php.net/?p=php-src.git;a=commit;h=d348cfb96f2543565691010ade5e0346338be5a7 There's an issue with PHP's EXIF module during a EXIF tag processing. When processing the Maker Note tag exif module fails to validate the data lenght, triggering an out of bounds read on a heap allocated value. The out of bounds happens when exif_process_IFD_in_MAKERNOTE() function calls strncmp() to compare the Maker Note's id string. An attacker may leverage this by crafting a speciall EXIF section, leading to information disclousure and possible DoS. This flaw has Low impact regarding Confidentiality as the attack has no control over the information which may be leaked and only a small chunck of heap data will be exposed. This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2020:3662 https://access.redhat.com/errata/RHSA-2020:3662 This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2019-11047 This issue has been addressed in the following products: Red Hat Software Collections for Red Hat Enterprise Linux 7 Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS Via RHSA-2020:5275 https://access.redhat.com/errata/RHSA-2020:5275 |