CVE-2019-11036


Heap over-read in PHP EXIF extension

When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.29, 7.2.x below 7.2.18 and 7.3.x below 7.3.5 can be caused to read past allocated buffer in exif_process_IFD_TAG function. This may lead to information disclosure or crash.



We have discovered 248,615 live websites that are affected by CVE-2019-11036.

Contact us to get more info




Affected Software

Product  PHP
Category Programming Languages
Vulnerable Versions
  • from 7.1 before 7.1.29
  • from 7.2 before 7.2.18
  • from 7.3 before 7.3.5
Total Vulnerable Versions507
Vulnerable Domains248,615 live websites (2.06% of PHP install base)


Common Weakness Enumeration


CWE-126 Buffer Over-read


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2019-11036 and the relative popularity of websites


Details

  • Published - Apr 30, 2019
  • Updated - Nov 1, 2019

Credits

  • Discovered by OSS-fuzz in https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=14050





Countries

United States35,517 websites



France107,981 websites
China18,367 websites
Russia9,313 websites
Japan7,233 websites
Italy6,410 websites
Poland5,737 websites
Korea, South5,308 websites
Belgium5,269 websites
Germany5,144 websites

TLDs

.com103,790 websites
.fr48,200 websites
.org9,794 websites
.net7,759 websites
.ru7,579 websites
.be5,913 websites
.it4,594 websites
.pl4,548 websites
.de3,438 websites
.cn2,919 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2019-11036 through included software libraries and plugins.



References


Websites affected by CVE-2019-11036

Top websites that are affected by CVE-2019-11036. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***.*****.cz Czech Republic*,***
*****.***.cn China*,***
***.*****.***.cn China*,***
*****.cn China*,***
***.*****.cn China*,***
******.*********.com China*,***
***.*********.com China*,***
*.***.cn China*,***
***.*.***.cn China*,***
******.com China*,***
See full domain list