CVE-2019-11043
php7.3 - security update
⚠ KEVEPSS 99.5%
描述
In some versions of PHP in certain configurations of FPM setup, it is possible to cause FPM module to write past allocated buffers allowing the possibility of remote code execution.
如何修補 CVE-2019-11043
要修補 CVE-2019-11043,請將受影響套件升級到下列已修補版本。
- Debian/php5—升級至 5.6.40+dfsg-0+deb8u7 或更新版本
- Debian/php7.0—升級至 7.0.33-0+deb9u6 或更新版本
- Debian/php7.3—升級至 7.3.11-1~deb10u1 或更新版本
CVE-2019-11043 正在被利用嗎?
是 — CVE-2019-11043 已列入 CISA Known Exploited Vulnerabilities (KEV) 清單,代表正在被實際利用,請立即修補。
受影響套件(3)
- from 0, < 5.6.40+dfsg-0+deb8u7
- from 0, < 7.0.33-0+deb9u6
- from 0, < 7.3.11-1~deb10u1