CVE-2019-11048


Temporary files are not cleaned after OOM when parsing HTTP request data

In PHP versions 7.2.x below 7.2.31, 7.3.x below 7.3.18 and 7.4.x below 7.4.6, when HTTP file uploads are allowed, supplying overly long filenames or field names could lead PHP engine to try to allocate oversized memory storage, hit the memory limit and stop processing the request, without cleaning up temporary files created by upload request. This potentially could lead to accumulation of uncleaned temporary files exhausting the disk space on the target server.



We have discovered 638,410 live websites that are affected by CVE-2019-11048.

Contact us to get more info




Affected Software

Product  PHP
Category Programming Languages
Vulnerable Versions
  • from 7.2 before 7.2.31
  • from 7.3 before 7.3.18
  • from 7.4 before 7.4.6
Total Vulnerable Versions507
Vulnerable Domains638,410 live websites (5.28% of PHP install base)


Common Weakness Enumeration


CWE-400 Uncontrolled Resource Consumption


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2019-11048 and the relative popularity of websites


Details

  • Published - May 11, 2020
  • Updated - Jul 23, 2021

Credits

  • jr at coredu dot mp





Countries

United States125,895 websites



France248,652 websites
Russia68,291 websites
China20,973 websites
Germany14,841 websites
Poland13,266 websites
Italy12,350 websites
Belgium11,659 websites
Japan10,251 websites
Spain10,164 websites

TLDs

.com260,137 websites
.fr110,636 websites
.ru65,356 websites
.org26,193 websites
.net17,838 websites
.be13,050 websites
.pl10,379 websites
.it9,300 websites
.de9,110 websites
.nl7,007 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2019-11048 through included software libraries and plugins.



References


Websites affected by CVE-2019-11048

Top websites that are affected by CVE-2019-11048. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***.*****.cz Czech Republic*,***
*.cn China*,***
***.*.cn China*,***
***.*****.pl Poland*,***
*******.com Germany*,***
*****.***.cn China*,***
***.*****.***.cn China*,***
*****.cn China*,***
***.*****.cn China*,***
***.*********.com China*,***
See full domain list