CVE-2019-11050

Use-after-free in exif parsing under memory sanitizer

When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.


We have discovered 390,801 live websites that are affected by CVE-2019-11050.

Test my site




Affected Software

Product  PHP
Category Programming Languages
Vulnerable Domains390,801 live websites (4.48% of PHP install base)
Vulnerable Versions
  • from 7.2 before 7.2.26
  • from 7.3 before 7.3.13
  • from 7.4 before 7.4.1
Vulnerable Versions Count40 versions ( 7.31% of all versions)


Common Weakness Enumeration

CWE-125 Out-of-bounds Read



Details

  • Published - Dec 23, 2019
  • Updated - Sep 16, 2024

Credits

  • Submitted by Nikita Popov

CVE-2019-11050 usage by Country

United States143,557 websites



France176,164 websites
China11,020 websites
Germany8,316 websites
Russia7,655 websites
Japan3,613 websites
Netherlands3,159 websites
Poland3,083 websites
GB2,941 websites
Italy2,356 websites

CVE-2019-11050 usage by TLD

.com155,444 websites
.fr69,498 websites
.ru59,318 websites
.org14,236 websites
.net10,462 websites
.be8,180 websites
.pl6,563 websites
.de5,184 websites
.it5,022 websites
.eu3,581 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2019-11050

Top websites that are affected by CVE-2019-11050. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*.cn China*,***
*****.***.cn China*,***
*****.cn China*,***
*********.com China*,***
*******.com United States*,***
*****.com United States*,***
******.com United States*,***
***.***.edu United States*,***
****.***.edu United States*,***
***.****.gov United States*,***
See full domain list

FAQ

CVE-2019-11050 is Out-of-bounds Read in PHP
A total of 390,801 websites have been identified as vulnerable to CVE-2019-11050, discovered through global website indexing conducted by WebTechSurvey.
PHP is susceptible to CVE-2019-11050 vulnerability.
PHP versions before 7.4.1 are vulnerable to CVE-2019-11050.
Version 7.4.1 of PHP addresses the CVE-2019-11050 security vulnerability.

References