CVE-2019-11046


Buffer underflow in bc_shift_addsub

In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP bcmath extension functions on some systems, including Windows, can be tricked into reading beyond the allocated space by supplying it with string containing characters that are identified as numeric by the OS but aren't ASCII numbers. This can read to disclosure of the content of some memory locations.



We have discovered 571,903 live websites that are affected by CVE-2019-11046.

Contact us to get more info




Affected Software

Product  PHP
Category Programming Languages
Vulnerable Versions
  • from 7.2 before 7.2.26
  • from 7.3 before 7.3.13
  • from 7.4 before 7.4.1
Total Vulnerable Versions507
Vulnerable Domains571,903 live websites (4.73% of PHP install base)


Common Weakness Enumeration


CWE-125 Out-of-bounds Read


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2019-11046 and the relative popularity of websites


Details

  • Published - Dec 17, 2019
  • Updated - Jul 23, 2021

Credits

  • Submitted by thomas-josef dot riedmaier at siemens dot com





Countries

United States109,222 websites



France242,217 websites
Russia64,041 websites
China18,980 websites
Germany11,556 websites
Belgium11,366 websites
Italy11,080 websites
Poland10,873 websites
Spain8,792 websites
Netherlands8,534 websites

TLDs

.com233,344 websites
.fr108,531 websites
.ru62,203 websites
.org22,565 websites
.net14,819 websites
.be12,774 websites
.pl8,622 websites
.it8,354 websites
.de7,057 websites
.nl6,242 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2019-11046 through included software libraries and plugins.



References


Websites affected by CVE-2019-11046

Top websites that are affected by CVE-2019-11046. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***.*****.cz Czech Republic*,***
*.cn China*,***
***.*.cn China*,***
*****.***.cn China*,***
***.*****.***.cn China*,***
*****.cn China*,***
***.*****.cn China*,***
***.*********.com China*,***
*.***.cn China*,***
***.*.***.cn China*,***
See full domain list