VDB

ALINUX2-SA-2019%3A0120

ALINUX2-SA-2019%3A0120 PUBLISHED CVSS 8.100000381469727 HIGH

Package updates are available for Alibaba Cloud Linux 2.1903 that fix the following vulnerabilities: CVE-2019-11043: In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.

Risk Scores

CVSS 3.0
8.100000381469727
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Alibaba Cloudphp

Timeline

  • Nov 2, 2019 CVE Published
  • Nov 2, 2019 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›