Bugzilla – Bug 1134322
VUL-0: CVE-2019-11036: php5,php72,php7,php53: php: buffer over-read in exif_process_IFD_TAG function leading to information disclosure
Last modified: 2021-09-14 12:49:58 UTC
rh#1707299 When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.29, 7.2.x below 7.2.18 and 7.3.x below 7.3.5 can be caused to read past allocated buffer in exif_process_IFD_TAG function. This may lead to information disclosure or crash. External Reference: https://bugs.php.net/bug.php?id=77950 Upstream commit: http://git.php.net/?p=php-src.git;a=commit;h=f80ad18afae2230c2c1802c7d829100af646874e References: https://bugzilla.redhat.com/show_bug.cgi?id=1707299 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-11036 http://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-11036.html http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11036 https://bugs.php.net/bug.php?id=77950
There is a testcase in the upstream commit. However, I get no invalid access reported by valgrind for 15/php7 to 11/php5, even with USE_ZEND_ALLOC=0.
Neither I get an asan report for 15/ImageMagick.
I mean: I do not get an asan report, neither.
Submitted for: 15/php7, 12/php72, 12/php7, 12/php5, 11sp3/php53, 11/php5 and 10sp3/php5.
An update workflow for this issue was started. This issue was rated as moderate. Please submit fixed packages until 2019-06-06. When done, reassign the bug to security-team@suse.de. https://swamp.suse.de/webswamp/wf/64286
SUSE-SU-2019:1325-1: An update that fixes 8 vulnerabilities is now available. Category: security (moderate) Bug References: 1128883,1128886,1128887,1128889,1128892,1132837,1132838,1134322 CVE References: CVE-2019-11034,CVE-2019-11035,CVE-2019-11036,CVE-2019-9637,CVE-2019-9638,CVE-2019-9639,CVE-2019-9640,CVE-2019-9675 Sources used: SUSE Linux Enterprise Software Development Kit 12-SP4 (src): php5-5.5.14-109.58.1 SUSE Linux Enterprise Software Development Kit 12-SP3 (src): php5-5.5.14-109.58.1 SUSE Linux Enterprise Module for Web Scripting 12 (src): php5-5.5.14-109.58.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2019:1360-1: An update that solves three vulnerabilities and has one errata is now available. Category: security (moderate) Bug References: 1132837,1132838,1133714,1134322 CVE References: CVE-2019-11034,CVE-2019-11035,CVE-2019-11036 Sources used: SUSE Linux Enterprise Software Development Kit 12-SP4 (src): php72-7.2.5-1.17.1 SUSE Linux Enterprise Software Development Kit 12-SP3 (src): php72-7.2.5-1.17.1 SUSE Linux Enterprise Module for Web Scripting 12 (src): php72-7.2.5-1.17.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2019:1365-1: An update that fixes three vulnerabilities is now available. Category: security (moderate) Bug References: 1132837,1132838,1134322 CVE References: CVE-2019-11034,CVE-2019-11035,CVE-2019-11036 Sources used: SUSE Linux Enterprise Software Development Kit 12-SP4 (src): php7-7.0.7-50.75.1 SUSE Linux Enterprise Software Development Kit 12-SP3 (src): php7-7.0.7-50.75.1 SUSE Linux Enterprise Module for Web Scripting 12 (src): php7-7.0.7-50.75.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
openSUSE-SU-2019:1501-1: An update that fixes three vulnerabilities is now available. Category: security (moderate) Bug References: 1132837,1132838,1134322 CVE References: CVE-2019-11034,CVE-2019-11035,CVE-2019-11036 Sources used: openSUSE Leap 42.3 (src): php7-7.0.7-61.1
openSUSE-SU-2019:1503-1: An update that fixes 8 vulnerabilities is now available. Category: security (moderate) Bug References: 1128883,1128886,1128887,1128889,1128892,1132837,1132838,1134322 CVE References: CVE-2019-11034,CVE-2019-11035,CVE-2019-11036,CVE-2019-9637,CVE-2019-9638,CVE-2019-9639,CVE-2019-9640,CVE-2019-9675 Sources used: openSUSE Leap 42.3 (src): php5-5.5.14-118.1
SUSE-SU-2019:1461-1: An update that solves 16 vulnerabilities and has two fixes is now available. Category: security (moderate) Bug References: 1118832,1119396,1126711,1126713,1126821,1126823,1126827,1127122,1128722,1128883,1128886,1128887,1128889,1128892,1129032,1132837,1132838,1134322 CVE References: CVE-2018-19935,CVE-2018-20783,CVE-2019-11034,CVE-2019-11035,CVE-2019-11036,CVE-2019-9020,CVE-2019-9021,CVE-2019-9022,CVE-2019-9023,CVE-2019-9024,CVE-2019-9637,CVE-2019-9638,CVE-2019-9639,CVE-2019-9640,CVE-2019-9641,CVE-2019-9675 Sources used: SUSE Linux Enterprise Module for Web Scripting 15 (src): php7-7.2.5-4.32.1 SUSE Linux Enterprise Module for Packagehub Subpackages 15 (src): php7-7.2.5-4.32.1 SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 (src): php7-7.2.5-4.32.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
openSUSE-SU-2019:1572-1: An update that solves 16 vulnerabilities and has two fixes is now available. Category: security (moderate) Bug References: 1118832,1119396,1126711,1126713,1126821,1126823,1126827,1127122,1128722,1128883,1128886,1128887,1128889,1128892,1129032,1132837,1132838,1134322 CVE References: CVE-2018-19935,CVE-2018-20783,CVE-2019-11034,CVE-2019-11035,CVE-2019-11036,CVE-2019-9020,CVE-2019-9021,CVE-2019-9022,CVE-2019-9023,CVE-2019-9024,CVE-2019-9637,CVE-2019-9638,CVE-2019-9639,CVE-2019-9640,CVE-2019-9641,CVE-2019-9675 Sources used: openSUSE Leap 15.1 (src): php7-7.2.5-lp151.6.3.1
openSUSE-SU-2019:1573-1: An update that solves 16 vulnerabilities and has two fixes is now available. Category: security (moderate) Bug References: 1118832,1119396,1126711,1126713,1126821,1126823,1126827,1127122,1128722,1128883,1128886,1128887,1128889,1128892,1129032,1132837,1132838,1134322 CVE References: CVE-2018-19935,CVE-2018-20783,CVE-2019-11034,CVE-2019-11035,CVE-2019-11036,CVE-2019-9020,CVE-2019-9021,CVE-2019-9022,CVE-2019-9023,CVE-2019-9024,CVE-2019-9637,CVE-2019-9638,CVE-2019-9639,CVE-2019-9640,CVE-2019-9641,CVE-2019-9675 Sources used: openSUSE Leap 15.0 (src): php7-7.2.5-lp150.2.19.1
released
This is an autogenerated message for OBS integration: This bug (1134322) was mentioned in https://build.opensuse.org/request/show/802846 Factory / php7
This is an autogenerated message for OBS integration: This bug (1134322) was mentioned in https://build.opensuse.org/request/show/802978 Factory / php7
This is an autogenerated message for OBS integration: This bug (1134322) was mentioned in https://build.opensuse.org/request/show/804946 Factory / php7
This is an autogenerated message for OBS integration: This bug (1134322) was mentioned in https://build.opensuse.org/request/show/805287 Factory / php7