I
n PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
Configuration 6 (hide)
|
History
03 Nov 2025, 19:23
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-11043 - US Government Resource |
22 Oct 2025, 00:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Oct 2025, 20:17
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Oct 2025, 19:17
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Nov 2024, 04:20
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : 7.5
v3 : 8.7 |
| References | () http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00011.html - Mailing List, Third Party Advisory | |
| References | () http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00014.html - Mailing List, Third Party Advisory | |
| References | () http://packetstormsecurity.com/files/156642/PHP-FPM-7.x-Remote-Code-Execution.html - Exploit, Third Party Advisory, VDB Entry | |
| References | () http://seclists.org/fulldisclosure/2020/Jan/40 - Mailing List, Third Party Advisory | |
| References | () https://access.redhat.com/errata/RHSA-2019:3286 - Third Party Advisory | |
| References | () https://access.redhat.com/errata/RHSA-2019:3287 - Third Party Advisory | |
| References | () https://access.redhat.com/errata/RHSA-2019:3299 - Third Party Advisory | |
| References | () https://access.redhat.com/errata/RHSA-2019:3300 - Third Party Advisory | |
| References | () https://access.redhat.com/errata/RHSA-2019:3724 - Third Party Advisory | |
| References | () https://access.redhat.com/errata/RHSA-2019:3735 - Third Party Advisory | |
| References | () https://access.redhat.com/errata/RHSA-2019:3736 - Third Party Advisory | |
| References | () https://access.redhat.com/errata/RHSA-2020:0322 - Third Party Advisory | |
| References | () https://bugs.php.net/bug.php?id=78599 - Exploit, Issue Tracking, Patch, Vendor Advisory | |
| References | () https://github.com/neex/phuip-fpizdam - Exploit, Third Party Advisory | |
| References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3W23TP6X4H7LB645FYZLUPNIRD5W3EPU/ - Mailing List, Third Party Advisory | |
| References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FSNBUSPKMLUHHOADROKNG5GDWDCRHT5M/ - Mailing List, Third Party Advisory | |
| References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T62LF4ZWVV7OMMIZFO6IFO5QLZKK7YRD/ - Mailing List, Third Party Advisory | |
| References | () https://seclists.org/bugtraq/2020/Jan/44 - Mailing List, Third Party Advisory | |
| References | () https://security.netapp.com/advisory/ntap-20191031-0003/ - Third Party Advisory | |
| References | () https://support.apple.com/kb/HT210919 - Third Party Advisory | |
| References | () https://support.f5.com/csp/article/K75408500?utm_source=f5support&%3Butm_medium=RSS - Third Party Advisory | |
| References | () https://usn.ubuntu.com/4166-1/ - Third Party Advisory | |
| References | () https://usn.ubuntu.com/4166-2/ - Third Party Advisory | |
| References | () https://www.debian.org/security/2019/dsa-4552 - Mailing List, Third Party Advisory | |
| References | () https://www.debian.org/security/2019/dsa-4553 - Mailing List, Third Party Advisory | |
| References | () https://www.synology.com/security/advisory/Synology_SA_19_36 - Third Party Advisory | |
| References | () https://www.tenable.com/security/tns-2021-14 - Third Party Advisory |
16 Jul 2024, 17:52
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.8_ppc64le:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:7.0_s390x:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_eus:8.1:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:8.0_ppc64le:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_server_aus:7.7:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.2_ppc64le:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_server_tus:8.8:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_for_arm_64_eus:8.6_aarch64:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_server_tus:8.4:*:*:*:*:*:*:* cpe:2.3:a:tenable:tenable.sc:*:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_for_power_big_endian:6.0_ppc64:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:7.7_ppc64le:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_for_arm_64_eus:8.1_aarch64:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_server_aus:8.4:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:8.2_s390x:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_for_power_big_endian_eus:7.7_ppc64:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_eus:8.4:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_eus:8.2:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_for_power_big_endian:7.0_ppc64:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:8.8_s390x:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_server_tus:8.2:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_for_arm_64:8.0_aarch64:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:8.0_s390x:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_for_arm_64_eus:8.2_aarch64:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_for_arm_64_eus:8.4_aarch64:*:*:*:*:*:*:* cpe:2.3:a:redhat:software_collections:1.0:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_for_arm_64_eus:8.8_aarch64:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:7.0_ppc64le:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.1_ppc64le:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_server_aus:8.2:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_server_tus:7.7:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:8.4_s390x:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_for_scientific_computing:7.0:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_server_tus:8.6:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:8.6_s390x:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_eus:8.8:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_eus_compute_node:7.7:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.4_ppc64le:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:8.1_s390x:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:6.0_s390x:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_server_aus:8.6:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:7.7_s390x:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.6_ppc64le:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_eus:8.6:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_eus:7.7:*:*:*:*:*:*:* |
|
| First Time |
Redhat enterprise Linux Eus
Redhat enterprise Linux Redhat enterprise Linux Eus Compute Node Redhat enterprise Linux For Power Big Endian Redhat Redhat enterprise Linux Server Aus Redhat enterprise Linux For Power Big Endian Eus Redhat enterprise Linux For Arm 64 Eus Redhat enterprise Linux For Arm 64 Redhat enterprise Linux For Ibm Z Systems Redhat enterprise Linux Workstation Redhat enterprise Linux For Power Little Endian Eus Redhat enterprise Linux For Power Little Endian Tenable Redhat enterprise Linux Server Redhat software Collections Redhat enterprise Linux Server Tus Fedoraproject fedora Tenable tenable.sc Redhat enterprise Linux Desktop Redhat enterprise Linux For Scientific Computing Redhat enterprise Linux For Ibm Z Systems Eus Fedoraproject |
|
| References | () http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00011.html - Mailing List, Third Party Advisory | |
| References | () http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00014.html - Mailing List, Third Party Advisory | |
| References | () http://packetstormsecurity.com/files/156642/PHP-FPM-7.x-Remote-Code-Execution.html - Exploit, Third Party Advisory, VDB Entry | |
| References | () http://seclists.org/fulldisclosure/2020/Jan/40 - Mailing List, Third Party Advisory | |
| References | () https://access.redhat.com/errata/RHSA-2019:3286 - Third Party Advisory | |
| References | () https://access.redhat.com/errata/RHSA-2019:3287 - Third Party Advisory | |
| References | () https://access.redhat.com/errata/RHSA-2019:3299 - Third Party Advisory | |
| References | () https://access.redhat.com/errata/RHSA-2019:3300 - Third Party Advisory | |
| References | () https://access.redhat.com/errata/RHSA-2019:3724 - Third Party Advisory | |
| References | () https://access.redhat.com/errata/RHSA-2019:3735 - Third Party Advisory | |
| References | () https://access.redhat.com/errata/RHSA-2019:3736 - Third Party Advisory | |
| References | () https://access.redhat.com/errata/RHSA-2020:0322 - Third Party Advisory | |
| References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3W23TP6X4H7LB645FYZLUPNIRD5W3EPU/ - Mailing List, Third Party Advisory | |
| References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FSNBUSPKMLUHHOADROKNG5GDWDCRHT5M/ - Mailing List, Third Party Advisory | |
| References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T62LF4ZWVV7OMMIZFO6IFO5QLZKK7YRD/ - Mailing List, Third Party Advisory | |
| References | () https://seclists.org/bugtraq/2020/Jan/44 - Mailing List, Third Party Advisory | |
| References | () https://security.netapp.com/advisory/ntap-20191031-0003/ - Third Party Advisory | |
| References | () https://support.apple.com/kb/HT210919 - Third Party Advisory | |
| References | () https://support.f5.com/csp/article/K75408500?utm_source=f5support&%3Butm_medium=RSS - Third Party Advisory | |
| References | () https://www.debian.org/security/2019/dsa-4552 - Mailing List, Third Party Advisory | |
| References | () https://www.debian.org/security/2019/dsa-4553 - Mailing List, Third Party Advisory | |
| References | () https://www.synology.com/security/advisory/Synology_SA_19_36 - Third Party Advisory | |
| References | () https://www.tenable.com/security/tns-2021-14 - Third Party Advisory |
Information
Published : 2019-10-28 15:15
Updated : 2025-11-03 19:23
NVD link : CVE-2019-11043
Mitre link : CVE-2019-11043
CVE.ORG link : CVE-2019-11043
JSON object : View
Products Affected
- enterprise_linux_for_ibm_z_systems
- enterprise_linux
- enterprise_linux_for_arm_64
- enterprise_linux_for_power_big_endian_eus
- enterprise_linux_for_power_little_endian_eus
- enterprise_linux_workstation
- enterprise_linux_desktop
- enterprise_linux_for_scientific_computing
- enterprise_linux_server
- enterprise_linux_for_power_little_endian
- enterprise_linux_for_power_big_endian
- software_collections
- enterprise_linux_server_aus
- enterprise_linux_server_tus
- enterprise_linux_for_ibm_z_systems_eus
- enterprise_linux_eus_compute_node
- enterprise_linux_for_arm_64_eus
- enterprise_linux_eus