CVE-2019-11046

⚪ Do wiadomości

Błąd w PHP bcmath umożliwia ujawnienie zawartości pamięci przez nieprawidłowe dane wejściowe.

CVSS
3.7
EPSS
4.1%
Exploit
none
Vendor
canonical
Opis źródłowy (NVD)

In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP bcmath extension functions on some systems, including Windows, can be tricked into reading beyond the allocated space by supplying it with string containing characters that are identified as numeric by the OS but aren't ASCII numbers. This can read to disclosure of the content of some memory locations.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS3.7
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)4.1%
Opublikowano (NVD)2019-12-23 03:15:11 UTC
Ostatnia modyfikacja (NVD)2026-08-17 14:50:49 UTC
Referencje