Security News > 2019 > October > PHP Bug Allows Remote Code-Execution on NGINX Servers

PHP Bug Allows Remote Code-Execution on NGINX Servers
2019-10-28 16:18

CVE-2019-11043 is trivial to exploit -- and a proof of concept is available.


News URL

https://threatpost.com/php-bug-rce-nginx-servers/149593/

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2019-10-28 CVE-2019-11043 Out-of-bounds Write vulnerability in multiple products
In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.
network
low complexity
php canonical debian fedoraproject tenable redhat CWE-787
critical
9.8

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
PHP 9 1 43 115 124 283
Nginx 2 0 3 1 4 8