CVE Database
/

CVE-2019-11049

Back to search

CVE-2019-11049

Published: Dec 23, 2019

Modified: Sep 16, 2024

PUBLISHED

CVSS v3.1

6.5

MEDIUM

Description

In PHP versions 7.3.x below 7.3.13 and 7.4.0 on Windows, when supplying custom headers to mail() function, due to mistake introduced in commit 78f4b4a2dcf92ddbccea1bb95f8390a18ac3342e, if the header is supplied in lowercase, this can result in double-freeing certain memory locations.

VendorProductVersions

PHP Group

PHP

affected
7.3.x - < 7.3.13
affected
7.4.x - < 7.4.1

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H

Attack Vector

Network

Attack Complexity

High

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

None

Integrity

Low

Availability

High

References

FEDORA-2019-437d94e271
vendor-advisory
x_refsource_FEDORA
FEDORA-2019-a54a622670
vendor-advisory
x_refsource_FEDORA
DSA-4626
vendor-advisory
x_refsource_DEBIAN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now