peter bassill · operator
$ cve CVE-2019-11043 JSON

CVE-2019-11043 KEV EXPLOIT

8.7
HIGH · CVSS 3.1 · EPSS 99.8% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-04-15.

Description

In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.

Scoring

CVSS8.7 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
EPSS99.78% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-120
On CISA KEVyes — remediate by 2022-04-15
Public exploityes
Published2019-10-28
Last modified2026-06-17

CISA KEV

NamePHP FastCGI Process Manager (FPM) Buffer Overflow Vulnerability
Added2022-03-25
Due2022-04-15
Vendor / productPHP / FastCGI Process Manager (FPM)
Ransomware useknown

Affected (23)

VendorProduct
canonicalubuntu linux
debiandebian linux
fedoraprojectfedora
phpphp
redhatenterprise linux
redhatenterprise linux desktop
redhatenterprise linux eus
redhatenterprise linux eus compute node
redhatenterprise linux for arm 64
redhatenterprise linux for arm 64 eus
redhatenterprise linux for ibm z systems
redhatenterprise linux for ibm z systems eus
redhatenterprise linux for power big endian
redhatenterprise linux for power big endian eus
redhatenterprise linux for power little endian
redhatenterprise linux for power little endian eus
redhatenterprise linux for scientific computing
redhatenterprise linux server
redhatenterprise linux server aus
redhatenterprise linux server tus
redhatenterprise linux workstation
redhatsoftware collections
tenabletenable.sc

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD