A AegiFlow
HIGHCVSS 8.7KNOWN EXPLOITEDRANSOMWARE: KNOWN

CVE-2019-11043

CVE-2019-11043 updated by NVD

Published
2022-03-25
Modified
2026-09-21
Sources
cisa-kev, nvd

Summary

In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.

Affected packages

EcosystemPackageAffected versionsFixed versions
PHPphp[object Object], [object Object], [object Object]

References

Includes data from the CISA Known Exploited Vulnerabilities catalog.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.