CVE-2019-11043


Underflow in PHP-FPM can lead to RCE

In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.



We have discovered 309,685 live websites that are affected by CVE-2019-11043.

Contact us to get more info




Affected Software

Product  PHP
Category Programming Languages
Vulnerable Versions
  • from 7.1 before 7.1.33
  • from 7.2 before 7.2.24
  • from 7.3 before 7.3.11
Total Vulnerable Versions507
Vulnerable Domains309,685 live websites (2.56% of PHP install base)


Common Weakness Enumeration


CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2019-11043 and the relative popularity of websites


Details

  • Published - Oct 22, 2019
  • Updated - Jul 23, 2021

Credits

  • Reported by Emil Lerner.





Countries

United States45,982 websites



France109,986 websites
China21,771 websites
Russia14,895 websites
Netherlands11,849 websites
Japan10,955 websites
Germany9,092 websites
Italy7,469 websites
Poland6,342 websites
GB5,967 websites

TLDs

.com126,753 websites
.fr48,933 websites
.ru12,357 websites
.org11,441 websites
.net9,468 websites
.nl8,856 websites
.be6,201 websites
.de6,097 websites
.it5,291 websites
.pl4,985 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2019-11043 through included software libraries and plugins.



References


Websites affected by CVE-2019-11043

Top websites that are affected by CVE-2019-11043. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***.*****.cz Czech Republic*,***
*.cn China*,***
***.*.cn China*,***
*****.***.cn China*,***
***.*****.***.cn China*,***
*****.cn China*,***
***.*****.cn China*,***
******.*********.com China*,***
***.*********.com China*,***
*.***.cn China*,***
See full domain list