CVE-2019-11035

Heap over-read in PHP EXIF extension

When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.28, 7.2.x below 7.2.17 and 7.3.x below 7.3.4 can be caused to read past allocated buffer in exif_iif_add_value function. This may lead to information disclosure or crash.


We have discovered 131,495 live websites that are affected by CVE-2019-11035.

Test my site




Affected Software

Product  PHP
Category Programming Languages
Vulnerable Domains131,495 live websites (1.51% of PHP install base)
Vulnerable Versions
  • from 7.1 before 7.1.28
  • from 7.2 before 7.2.17
  • from 7.3 before 7.3.4
Vulnerable Versions Count49 versions ( 8.96% of all versions)


Common Weakness Enumeration

CWE-125 Out-of-bounds Read



Details

  • Published - Apr 18, 2019
  • Updated - Sep 17, 2024

Credits

  • Found by OSS-Fuzz in https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=13938

CVE-2019-11035 usage by Country

United States18,640 websites



France68,881 websites
China8,924 websites
Russia5,669 websites
Japan5,050 websites
Germany3,228 websites
Poland1,503 websites
Ukraine1,301 websites
GB1,225 websites
Italy1,225 websites

CVE-2019-11035 usage by TLD

.com54,044 websites
.fr26,759 websites
.ru5,169 websites
.net4,225 websites
.org4,199 websites
.be3,343 websites
.pl2,918 websites
.it2,642 websites
.de2,115 websites
.eu1,585 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2019-11035

Top websites that are affected by CVE-2019-11035. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.***.cn China*,***
*****.cn China*,***
******.*********.com China*,***
*********.com China*,***
*****.**.com China*,***
*****.org United States*,***
********.com United States*,***
***.com United States*,***
********.com United States**,***
*****.***.tr Turkey**,***
See full domain list

FAQ

CVE-2019-11035 is Out-of-bounds Read in PHP
A total of 131,495 websites have been identified as vulnerable to CVE-2019-11035, discovered through global website indexing conducted by WebTechSurvey.
PHP is susceptible to CVE-2019-11035 vulnerability.
PHP versions before 7.3.4 are vulnerable to CVE-2019-11035.
Version 7.3.4 of PHP addresses the CVE-2019-11035 security vulnerability.

References