CVE-2019-9024Out-of-bounds Read in PHP

CWE-125Out-of-bounds Read9 documents7 sources
Severity
7.5HIGHNVD
OSV9.8
EPSS
13.7%
top 5.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 22
Latest updateJan 27

Description

An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. xmlrpc_decode() can allow a hostile XMLRPC server to cause PHP to read memory outside of allocated areas in base64_decode_xmlrpc in ext/xmlrpc/libxmlrpc/base64.c.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

NVDphp/php7.0.07.1.26+3
Ubuntuphp5/php5< 5.5.9+dfsg-1ubuntu4.27
NVDopensuse/leap42.3

Also affects: Debian Linux 9.0, Ubuntu Linux 12.04, 14.04, 16.04

Patches

🔴Vulnerability Details

3
GHSA
GHSA-v89c-qc56-rr3m: An issue was discovered in PHP before 52022-05-14
OSV
php5, php7.0 vulnerabilities2019-03-06
OSV
CVE-2019-9024: An issue was discovered in PHP before 52019-02-22

📋Vendor Advisories

4
CISA ICS
Festo Didactic SE MES PC2026-01-27
Ubuntu
PHP vulnerabilities2019-03-12
Ubuntu
PHP vulnerabilities2019-03-06
Red Hat
php: Out-of-bounds read in base64_decode_xmlrpc in ext/xmlrpc/libxmlrpc/base64.c2019-02-22

💬Community

1
Bugzilla
CVE-2019-9024 php: Out-of-bounds read in base64_decode_xmlrpc in ext/xmlrpc/libxmlrpc/base64.c2019-03-05