CVE-2019-11035


Heap over-read in PHP EXIF extension

When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.28, 7.2.x below 7.2.17 and 7.3.x below 7.3.4 can be caused to read past allocated buffer in exif_iif_add_value function. This may lead to information disclosure or crash.



We have discovered 239,735 live websites that are affected by CVE-2019-11035.

Contact us to get more info




Affected Software

Product  PHP
Category Programming Languages
Vulnerable Versions
  • from 7.1 before 7.1.28
  • from 7.2 before 7.2.17
  • from 7.3 before 7.3.4
Total Vulnerable Versions507
Vulnerable Domains239,735 live websites (1.98% of PHP install base)


Common Weakness Enumeration


CWE-125 Out-of-bounds Read


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2019-11035 and the relative popularity of websites


Details

  • Published - Apr 1, 2019
  • Updated - Nov 1, 2019

Credits

  • Found by OSS-Fuzz in https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=13938





Countries

United States33,195 websites



France107,746 websites
China16,772 websites
Russia8,419 websites
Japan6,930 websites
Italy6,328 websites
Poland5,659 websites
Belgium5,225 websites
Korea, South5,176 websites
Germany4,918 websites

TLDs

.com99,913 websites
.fr48,134 websites
.org9,512 websites
.net7,487 websites
.ru6,772 websites
.be5,873 websites
.it4,539 websites
.pl4,497 websites
.de3,297 websites
.eu2,670 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2019-11035 through included software libraries and plugins.



References


Websites affected by CVE-2019-11035

Top websites that are affected by CVE-2019-11035. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***.*****.cz Czech Republic*,***
*****.***.cn China*,***
***.*****.***.cn China*,***
*****.cn China*,***
***.*****.cn China*,***
******.*********.com China*,***
***.*********.com China*,***
*.***.cn China*,***
***.*.***.cn China*,***
******.com China*,***
See full domain list