CVE-2019-9637

An issue was discovered in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. Due to the way rename() across filesystems is implemented, it is possible that file being renamed is briefly available with wrong permissions while the rename is ongoing, thus enabling unauthorized users to access the data.
References
Link Resource
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00104.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00012.html
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00041.html
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00044.html
https://access.redhat.com/errata/RHSA-2019:2519
https://access.redhat.com/errata/RHSA-2019:3299
https://bugs.php.net/bug.php?id=77630 Issue Tracking Patch Vendor Advisory
https://lists.debian.org/debian-lts-announce/2019/03/msg00043.html Mailing List Third Party Advisory
https://security.netapp.com/advisory/ntap-20190502-0007/ Third Party Advisory
https://support.f5.com/csp/article/K53825211 Third Party Advisory
https://usn.ubuntu.com/3922-1/ Third Party Advisory
https://usn.ubuntu.com/3922-2/ Third Party Advisory
https://usn.ubuntu.com/3922-3/ Third Party Advisory
https://www.debian.org/security/2019/dsa-4403 Third Party Advisory
https://www.tenable.com/security/tns-2019-07
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00104.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00012.html
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00041.html
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00044.html
https://access.redhat.com/errata/RHSA-2019:2519
https://access.redhat.com/errata/RHSA-2019:3299
https://bugs.php.net/bug.php?id=77630 Issue Tracking Patch Vendor Advisory
https://lists.debian.org/debian-lts-announce/2019/03/msg00043.html Mailing List Third Party Advisory
https://security.netapp.com/advisory/ntap-20190502-0007/ Third Party Advisory
https://support.f5.com/csp/article/K53825211 Third Party Advisory
https://usn.ubuntu.com/3922-1/ Third Party Advisory
https://usn.ubuntu.com/3922-2/ Third Party Advisory
https://usn.ubuntu.com/3922-3/ Third Party Advisory
https://www.debian.org/security/2019/dsa-4403 Third Party Advisory
https://www.tenable.com/security/tns-2019-07
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*

Configuration 4 (hide)

cpe:2.3:o:opensuse:leap:42.3:*:*:*:*:*:*:*

Configuration 5 (hide)

cpe:2.3:a:netapp:storage_automation_store:-:*:*:*:*:*:*:*

History

21 Nov 2024, 04:52

Type Values Removed Values Added
References () http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00104.html - Mailing List, Third Party Advisory () http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00104.html - Mailing List, Third Party Advisory
References () http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00012.html - () http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00012.html -
References () http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00041.html - () http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00041.html -
References () http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00044.html - () http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00044.html -
References () https://access.redhat.com/errata/RHSA-2019:2519 - () https://access.redhat.com/errata/RHSA-2019:2519 -
References () https://access.redhat.com/errata/RHSA-2019:3299 - () https://access.redhat.com/errata/RHSA-2019:3299 -
References () https://bugs.php.net/bug.php?id=77630 - Issue Tracking, Patch, Vendor Advisory () https://bugs.php.net/bug.php?id=77630 - Issue Tracking, Patch, Vendor Advisory
References () https://lists.debian.org/debian-lts-announce/2019/03/msg00043.html - Mailing List, Third Party Advisory () https://lists.debian.org/debian-lts-announce/2019/03/msg00043.html - Mailing List, Third Party Advisory
References () https://security.netapp.com/advisory/ntap-20190502-0007/ - Third Party Advisory () https://security.netapp.com/advisory/ntap-20190502-0007/ - Third Party Advisory
References () https://support.f5.com/csp/article/K53825211 - Third Party Advisory () https://support.f5.com/csp/article/K53825211 - Third Party Advisory
References () https://usn.ubuntu.com/3922-1/ - Third Party Advisory () https://usn.ubuntu.com/3922-1/ - Third Party Advisory
References () https://usn.ubuntu.com/3922-2/ - Third Party Advisory () https://usn.ubuntu.com/3922-2/ - Third Party Advisory
References () https://usn.ubuntu.com/3922-3/ - Third Party Advisory () https://usn.ubuntu.com/3922-3/ - Third Party Advisory
References () https://www.debian.org/security/2019/dsa-4403 - Third Party Advisory () https://www.debian.org/security/2019/dsa-4403 - Third Party Advisory
References () https://www.tenable.com/security/tns-2019-07 - () https://www.tenable.com/security/tns-2019-07 -

Information

Published : 2019-03-09 00:29

Updated : 2024-11-21 04:52


NVD link : CVE-2019-9637

Mitre link : CVE-2019-9637

CVE.ORG link : CVE-2019-9637


JSON object : View

Products Affected

php

  • php

canonical

  • ubuntu_linux

netapp

  • storage_automation_store

opensuse

  • leap

debian

  • debian_linux
CWE
CWE-264

Permissions, Privileges, and Access Controls