Umbra Wiki cve cve/CVE-2019-11043
Back to wiki

CVE-2019-11043 — PHP FastCGI Process Manager (FPM) Buffer Overflow Vulnerability

provenance: imported · CVE: CVE-2019-11043

CVE-2019-11043: PHP FastCGI Process Manager (FPM) Buffer Overflow Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project PHP
Product FastCGI Process Manager (FPM)
Date added 2022-03-25
Due date 2022-04-15
Ransomware campaign use Known

Description

In some versions of PHP in certain configurations of FPM setup, it is possible to cause FPM module to write past allocated buffers allowing the possibility of remote code execution.

Required action (CISA)

Apply updates per vendor instructions.

Notes

https://nvd.nist.gov/vuln/detail/CVE-2019-11043

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2019-11043
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog