CVE-2019-11044
⚪ Do wiadomości
Funkcja link() w PHP na Windows akceptuje pliki z wbudowanym bajtem \0, co może prowadzić do luk w zabezpieczeniach.
CVSS
3.7
EPSS
5.1%
Exploit
poc
Vendor
php
Opis źródłowy (NVD)
In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 on Windows, PHP link() function accepts filenames with embedded \0 byte and treats them as terminating at that byte. This could lead to security vulnerabilities, e.g. in applications checking paths that the code is allowed to access.
exploit
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 3.7 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 5.1% |
| Opublikowano (NVD) | 2019-12-23 03:15:10 UTC |
| Ostatnia modyfikacja (NVD) | 2026-08-17 14:50:49 UTC |
Referencje
- https://bugs.php.net/bug.php?id=78862 (security@php.net) [Exploit, Mailing List, Patch, Vendor Advisory]
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N7GCOAE6KVHYJ3UQ4KLPLTGSLX6IRVRN/ (security@php.net)
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XWRQPYXVG43Q7DXMXH6UVWMKWGUW552F/ (security@php.net)
- https://security.netapp.com/advisory/ntap-20200103-0002/ (security@php.net) [Third Party Advisory]
- https://www.tenable.com/security/tns-2021-14 (security@php.net) [Third Party Advisory]