CVE-2019-11046

Description

In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP bcmath extension functions on some systems, including Windows, can be tricked into reading beyond the allocated space by supplying it with string containing characters that are identified as numeric by the OS but arent ASCII numbers. This can read to disclosure of the content of some memory locations.

Risk Information

Base Score
5.3
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS Score
Exploitation Probability
8.245

Associated Vulnerability

VulnerabilityOS Platform
server-side, HTML-embedded scripting language (metapackage) (USN-4239-1) php7.0-cgi_7.0.33-0ubuntu0.16.04.9_i386.debLinux
server-side, HTML-embedded scripting language (metapackage) (USN-4239-1) php7.0-cgi_7.0.33-0ubuntu0.16.04.9_amd64.debLinux
server-side, HTML-embedded scripting language (metapackage) (USN-4239-1) php7.0-cli_7.0.33-0ubuntu0.16.04.9_i386.debLinux
server-side, HTML-embedded scripting language (metapackage) (USN-4239-1) php7.0-cli_7.0.33-0ubuntu0.16.04.9_amd64.debLinux
server-side, HTML-embedded scripting language (metapackage) (USN-4239-1) php7.0-fpm_7.0.33-0ubuntu0.16.04.9_i386.debLinux
server-side, HTML-embedded scripting language (metapackage) (USN-4239-1) php7.0-fpm_7.0.33-0ubuntu0.16.04.9_amd64.debLinux
server-side, HTML-embedded scripting language (metapackage) (USN-4239-1) php7.2-cgi_7.2.24-0ubuntu0.18.04.2_i386.debLinux
server-side, HTML-embedded scripting language (metapackage) (USN-4239-1) php7.2-cgi_7.2.24-0ubuntu0.18.04.2_amd64.debLinux
server-side, HTML-embedded scripting language (metapackage) (USN-4239-1) php7.2-cgi_7.2.24-0ubuntu0.19.04.2_i386.debLinux
server-side, HTML-embedded scripting language (metapackage) (USN-4239-1) php7.2-cgi_7.2.24-0ubuntu0.19.04.2_amd64.debLinux
server-side, HTML-embedded scripting language (metapackage) (USN-4239-1) php7.2-cli_7.2.24-0ubuntu0.18.04.2_i386.debLinux
server-side, HTML-embedded scripting language (metapackage) (USN-4239-1) php7.2-cli_7.2.24-0ubuntu0.18.04.2_amd64.debLinux
server-side, HTML-embedded scripting language (metapackage) (USN-4239-1) php7.2-cli_7.2.24-0ubuntu0.19.04.2_i386.debLinux
server-side, HTML-embedded scripting language (metapackage) (USN-4239-1) php7.2-cli_7.2.24-0ubuntu0.19.04.2_amd64.debLinux
server-side, HTML-embedded scripting language (metapackage) (USN-4239-1) php7.2-fpm_7.2.24-0ubuntu0.18.04.2_i386.debLinux
server-side, HTML-embedded scripting language (metapackage) (USN-4239-1) php7.2-fpm_7.2.24-0ubuntu0.18.04.2_amd64.debLinux
server-side, HTML-embedded scripting language (metapackage) (USN-4239-1) php7.2-fpm_7.2.24-0ubuntu0.19.04.2_i386.debLinux
server-side, HTML-embedded scripting language (metapackage) (USN-4239-1) php7.2-fpm_7.2.24-0ubuntu0.19.04.2_amd64.debLinux
server-side, HTML-embedded scripting language (metapackage) (USN-4239-1) php7.3-cgi_7.3.11-0ubuntu0.19.10.2_i386.debLinux
server-side, HTML-embedded scripting language (metapackage) (USN-4239-1) php7.3-cgi_7.3.11-0ubuntu0.19.10.2_amd64.debLinux
server-side, HTML-embedded scripting language (metapackage) (USN-4239-1) php7.3-cli_7.3.11-0ubuntu0.19.10.2_i386.debLinux
server-side, HTML-embedded scripting language (metapackage) (USN-4239-1) php7.3-cli_7.3.11-0ubuntu0.19.10.2_amd64.debLinux
server-side, HTML-embedded scripting language (metapackage) (USN-4239-1) php7.3-fpm_7.3.11-0ubuntu0.19.10.2_i386.debLinux
server-side, HTML-embedded scripting language (metapackage) (USN-4239-1) php7.3-fpm_7.3.11-0ubuntu0.19.10.2_amd64.debLinux
server-side, HTML-embedded scripting language (metapackage) (USN-4239-1) php7.0-bcmath_7.0.33-0ubuntu0.16.04.9_i386.debLinux
server-side, HTML-embedded scripting language (metapackage) (USN-4239-1) php7.0-bcmath_7.0.33-0ubuntu0.16.04.9_amd64.debLinux
server-side, HTML-embedded scripting language (metapackage) (USN-4239-1) php7.0-xmlrpc_7.0.33-0ubuntu0.16.04.9_i386.debLinux
server-side, HTML-embedded scripting language (metapackage) (USN-4239-1) php7.0-xmlrpc_7.0.33-0ubuntu0.16.04.9_amd64.debLinux
server-side, HTML-embedded scripting language (metapackage) (USN-4239-1) php7.2-bcmath_7.2.24-0ubuntu0.18.04.2_i386.debLinux
server-side, HTML-embedded scripting language (metapackage) (USN-4239-1) php7.2-bcmath_7.2.24-0ubuntu0.18.04.2_amd64.debLinux
server-side, HTML-embedded scripting language (metapackage) (USN-4239-1) php7.2-bcmath_7.2.24-0ubuntu0.19.04.2_i386.debLinux
server-side, HTML-embedded scripting language (metapackage) (USN-4239-1) php7.2-bcmath_7.2.24-0ubuntu0.19.04.2_amd64.debLinux
server-side, HTML-embedded scripting language (metapackage) (USN-4239-1) php7.2-xmlrpc_7.2.24-0ubuntu0.18.04.2_i386.debLinux
server-side, HTML-embedded scripting language (metapackage) (USN-4239-1) php7.2-xmlrpc_7.2.24-0ubuntu0.18.04.2_amd64.debLinux
server-side, HTML-embedded scripting language (metapackage) (USN-4239-1) php7.2-xmlrpc_7.2.24-0ubuntu0.19.04.2_i386.debLinux
server-side, HTML-embedded scripting language (metapackage) (USN-4239-1) php7.2-xmlrpc_7.2.24-0ubuntu0.19.04.2_amd64.debLinux
server-side, HTML-embedded scripting language (metapackage) (USN-4239-1) php7.3-bcmath_7.3.11-0ubuntu0.19.10.2_i386.debLinux
server-side, HTML-embedded scripting language (metapackage) (USN-4239-1) php7.3-bcmath_7.3.11-0ubuntu0.19.10.2_amd64.debLinux
server-side, HTML-embedded scripting language (metapackage) (USN-4239-1) php7.3-xmlrpc_7.3.11-0ubuntu0.19.10.2_i386.debLinux
server-side, HTML-embedded scripting language (metapackage) (USN-4239-1) php7.3-xmlrpc_7.3.11-0ubuntu0.19.10.2_amd64.debLinux
server-side, HTML-embedded scripting language (metapackage) (USN-4239-1) php7.0-mbstring_7.0.33-0ubuntu0.16.04.9_i386.debLinux
server-side, HTML-embedded scripting language (metapackage) (USN-4239-1) php7.0-mbstring_7.0.33-0ubuntu0.16.04.9_amd64.debLinux
server-side, HTML-embedded scripting language (metapackage) (USN-4239-1) php7.2-mbstring_7.2.24-0ubuntu0.18.04.2_i386.debLinux
server-side, HTML-embedded scripting language (metapackage) (USN-4239-1) php7.2-mbstring_7.2.24-0ubuntu0.18.04.2_amd64.debLinux
server-side, HTML-embedded scripting language (metapackage) (USN-4239-1) php7.2-mbstring_7.2.24-0ubuntu0.19.04.2_i386.debLinux
server-side, HTML-embedded scripting language (metapackage) (USN-4239-1) php7.2-mbstring_7.2.24-0ubuntu0.19.04.2_amd64.debLinux
server-side, HTML-embedded scripting language (metapackage) (USN-4239-1) php7.3-mbstring_7.3.11-0ubuntu0.19.10.2_i386.debLinux
server-side, HTML-embedded scripting language (metapackage) (USN-4239-1) php7.3-mbstring_7.3.11-0ubuntu0.19.10.2_amd64.debLinux
server-side, HTML-embedded scripting language (metapackage) (USN-4239-1) libapache2-mod-php7.0_7.0.33-0ubuntu0.16.04.9_i386.debLinux
server-side, HTML-embedded scripting language (metapackage) (USN-4239-1) libapache2-mod-php7.0_7.0.33-0ubuntu0.16.04.9_amd64.debLinux
server-side, HTML-embedded scripting language (metapackage) (USN-4239-1) libapache2-mod-php7.2_7.2.24-0ubuntu0.18.04.2_i386.debLinux
server-side, HTML-embedded scripting language (metapackage) (USN-4239-1) libapache2-mod-php7.2_7.2.24-0ubuntu0.18.04.2_amd64.debLinux
server-side, HTML-embedded scripting language (metapackage) (USN-4239-1) libapache2-mod-php7.2_7.2.24-0ubuntu0.19.04.2_i386.debLinux
server-side, HTML-embedded scripting language (metapackage) (USN-4239-1) libapache2-mod-php7.2_7.2.24-0ubuntu0.19.04.2_amd64.debLinux
server-side, HTML-embedded scripting language (metapackage) (USN-4239-1) libapache2-mod-php7.3_7.3.11-0ubuntu0.19.10.2_i386.debLinux
server-side, HTML-embedded scripting language (metapackage) (USN-4239-1) libapache2-mod-php7.3_7.3.11-0ubuntu0.19.10.2_amd64.debLinux
php7.3 security update(DSA-4626-1) php7.3_7.3.14-1~deb10u1_all.debLinux
php7.0 security update(DSA-4628-1) php7.0_7.0.33-0+deb9u7_all.debLinux
server-side, HTML-embedded scripting language (metapackage) (USN-4239-1) php7.2-bcmath_7.2.24-0ubuntu0.18.04.2_i386.debLinux
server-side, HTML-embedded scripting language (metapackage) (USN-4239-1) php7.2-bcmath_7.2.24-0ubuntu0.18.04.2_amd64.debLinux
server-side, HTML-embedded scripting language (metapackage) (USN-4239-1) php7.2-xmlrpc_7.2.24-0ubuntu0.18.04.2_i386.debLinux
server-side, HTML-embedded scripting language (metapackage) (USN-4239-1) php7.2-xmlrpc_7.2.24-0ubuntu0.18.04.2_amd64.debLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234