CVE-2019-9640
An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3 (CVE-2019-9640)
highEPSS 6.2%
Description
Metrics
Severity
high
93.32
no public PoC known
7.5
93.1 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
Published
2019-03-08 23:00 UTC
—
Affected operating systems
linux
debian / debian_linux8.0
linux
debian / debian_linux9.0
linux
opensuse / leap15.0
linux
opensuse / leap15.1
linux
opensuse / leap42.3
linux
canonical / ubuntu_linux12.04
linux
canonical / ubuntu_linux14.04
linux
canonical / ubuntu_linux16.04
linux
canonical / ubuntu_linux18.04
linux
canonical / ubuntu_linux18.10
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
netapp
storage_automation_store
php
php7.1.0 – 7.1.27
php
php7.2.0 – 7.2.16
php
php7.3.0 – 7.3.3
redhat
software_collections
References & sources
- https://www.debian.org/security/2019/dsa-4403vendor-advisoryx_refsource_DEBIAN
- https://bugs.php.net/bug.php?id=77540x_refsource_MISC
- https://usn.ubuntu.com/3922-1/vendor-advisoryx_refsource_UBUNTU
- https://lists.debian.org/debian-lts-announce/2019/03/msg00043.htmlmailing-listx_refsource_MLIST
- https://usn.ubuntu.com/3922-2/vendor-advisoryx_refsource_UBUNTU
- https://usn.ubuntu.com/3922-3/vendor-advisoryx_refsource_UBUNTU
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00104.htmlvendor-advisoryx_refsource_SUSE
- https://security.netapp.com/advisory/ntap-20190502-0007/x_refsource_CONFIRM
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00012.htmlvendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00041.htmlvendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00044.htmlvendor-advisoryx_refsource_SUSE
- https://access.redhat.com/errata/RHSA-2019:2519vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2019:3299vendor-advisoryx_refsource_REDHAT
IDCVE-2019-9640