CVE-2019-11049


mail() may release string with refcount==1 twice

In PHP versions 7.3.x below 7.3.13 and 7.4.0 on Windows, when supplying custom headers to mail() function, due to mistake introduced in commit 78f4b4a2dcf92ddbccea1bb95f8390a18ac3342e, if the header is supplied in lowercase, this can result in double-freeing certain memory locations.



We have discovered 378,377 live websites that are affected by CVE-2019-11049.

Contact us to get more info




Affected Software

Product  PHP
Category Programming Languages
Vulnerable Versions
  • from 7.3 before 7.3.13
  • from 7.4 before 7.4.1
Total Vulnerable Versions507
Vulnerable Domains378,377 live websites (3.13% of PHP install base)


Common Weakness Enumeration


CWE-415 Double Free


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2019-11049 and the relative popularity of websites


Details

  • Published - Dec 17, 2019
  • Updated - Jul 23, 2021

Credits

  • Submitted by Christoph M. Becker





Countries

United States84,660 websites



France202,788 websites
Belgium9,251 websites
Poland8,010 websites
Russia7,544 websites
Italy7,377 websites
China6,570 websites
Spain6,013 websites
Germany5,427 websites
Canada4,916 websites

TLDs

.com175,566 websites
.fr91,017 websites
.org17,434 websites
.net10,642 websites
.be10,428 websites
.ru6,733 websites
.pl6,398 websites
.it5,724 websites
.eu4,079 websites
.es3,532 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2019-11049 through included software libraries and plugins.



References


Websites affected by CVE-2019-11049

Top websites that are affected by CVE-2019-11049. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
******.com France*,***
**********.com France*,***
************.org France*,***
***.******.com France*,***
*************.com GB*,***
***.***********.com GB**,***
******.****.ru Russia**,***
*******.**.kr Korea, South**,***
*******************.com United States**,***
**************.com United States**,***
See full domain list