CISA KEV 정보
| 취약점명 | PHP FastCGI Process Manager (FPM) Buffer Overflow Vulnerability |
|---|---|
| 설명 | In some versions of PHP in certain configurations of FPM setup, it is possible to cause FPM module to write past allocated buffers allowing the possibility of remote code execution. |
| 조치사항 | Apply updates per vendor instructions. |
| 랜섬웨어 캠페인 악용 | Known |
| CWE | CWE-120 |
| 등록일 (KEV) | 2022-03-25 |
| 조치 기한 | 2022-04-15 |
| 추가 참고 | https://nvd.nist.gov/vuln/detail/CVE-2019-11043 |
NVD 상세 정보
CVSS v3.1: 8.7 HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:NCVSS v2.0: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P설명: In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.
CWE: CWE-120 | CWE-787
참조
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00011.html [Mailing List, Third Party Advisory]
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00014.html [Mailing List, Third Party Advisory]
- http://packetstormsecurity.com/files/156642/PHP-FPM-7.x-Remote-Code-Execution.html [Exploit, Third Party Advisory, VDB Entry]
- http://seclists.org/fulldisclosure/2020/Jan/40 [Mailing List, Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2019:3286 [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2019:3287 [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2019:3299 [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2019:3300 [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2019:3724 [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2019:3735 [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2019:3736 [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2020:0322 [Third Party Advisory]
- https://bugs.php.net/bug.php?id=78599 [Exploit, Issue Tracking, Patch, Vendor Advisory]
- https://github.com/neex/phuip-fpizdam [Exploit, Third Party Advisory]
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3W23TP6X4H7LB645FYZLUPNIRD5W3EPU/ [Mailing List, Third Party Advisory]
- ... 외 40건
This product uses the NVD API but is not endorsed or certified by the NVD.