[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS-2019-1240

ID: oval:org.secpod.oval:def:1601033Date: (C)2019-07-30   (M)2024-04-17
Class: PATCHFamily: unix




Function iconv_mime_decode_headers in PHP may perform out-of-buffer read due to integer overflow when parsing MIME headers. This may lead to information disclosure or crash.When using gdImageCreateFromXbm function of PHP gd extension, it is possible to supply data that will cause the function to use the value of uninitialized variable. This may lead to disclosing contents of the stack that has been left there by previous code. When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data function, in PHP it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash

Platform:
Amazon Linux AMI
Product:
php71
php72
php73
Reference:
ALAS-2019-1240
CVE-2019-11039
CVE-2019-11038
CVE-2019-11040
CVE    3
CVE-2019-11038
CVE-2019-11040
CVE-2019-11039
CPE    4
cpe:/o:amazon:linux
cpe:/a:php:php72
cpe:/a:php:php71
cpe:/a:php:php73
...

© SecPod Technologies