Bug 1788258 (CVE-2019-11050)
Summary: | CVE-2019-11050 php: Out of bounds read when parsing EXIF information | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Guilherme de Almeida Suckevicz <gsuckevi> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | low | Docs Contact: | |
Priority: | low | ||
Version: | unspecified | CC: | fedora, hhorak, jorton, rcollet, webstack-team, yozone |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | php 7.4.1, php 7.3.13, php 7.2.26 | Doc Type: | If docs needed, set a value |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2020-09-08 13:18:40 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1788259, 1790938, 1790939, 1790940, 1790941, 1790942, 1857705 | ||
Bug Blocks: | 1788265 |
Description
Guilherme de Almeida Suckevicz
2020-01-06 20:26:28 UTC
Created php tracking bugs for this issue: Affects: fedora-all [bug 1788259] Upstream commit for this issue: http://git.php.net/?p=php-src.git;a=commit;h=c14eb8de974fc8a4d74f3515424c293bc7a40fba There's an issue with EXIF module in PHP when exif tries to read maker notes from a given image metadata. When iterating on exif directories on exif_process_IFD_in_MAKERNOTE() starts to walk the buffer by the offset read but it doesn't decrement the remaining length of the buffer by the same proportion. An attack may leverage this issue by crafting an image with a malicious EXIF information, leading to Confidentiality impact and eventually DoS. Both confidentiality and availability impact may be considered low. The attack has access just to a small amount of bytes from process heap and only a the single execution for this is affected. This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2020:3662 https://access.redhat.com/errata/RHSA-2020:3662 This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2019-11050 This issue has been addressed in the following products: Red Hat Software Collections for Red Hat Enterprise Linux 7 Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS Via RHSA-2020:5275 https://access.redhat.com/errata/RHSA-2020:5275 |