CVE-2019-11043 PHP+Nginx remote code execution

Bug #1849620 reported by A Z
26
This bug affects 4 people
Affects Status Importance Assigned to Milestone
php-defaults (Ubuntu)
Fix Released
Undecided
Ubuntu Security Team

CVE References

A Z (azaagman)
information type: Private Security → Public
A Z (azaagman)
Changed in vlc (Ubuntu):
assignee: nobody → A Z (azaagman)
status: New → Invalid
Revision history for this message
Christian Ehrhardt  (paelzer) wrote :

Hi A Z,
I'm not sure what VLC has to do with it, but I know that the CVE is being dealt with by the security team at the moment.

=> https://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-11043.html

@Marc it is assigned to you so I subscribe you here to close the bug when it got released.

no longer affects: vlc (Ubuntu)
Revision history for this message
Launchpad Janitor (janitor) wrote :

Status changed to 'Confirmed' because the bug affects multiple users.

Changed in php-defaults (Ubuntu):
status: New → Confirmed
Changed in php-defaults (Ubuntu):
assignee: nobody → Ubuntu Security Team (ubuntu-security)
Revision history for this message
mig5 (mig5) wrote :

I see that updated packages have come out for PHP 7 (https://usn.ubuntu.com/4166-1/), thanks!

Will you also do a release for PHP 5 on the ESM 14.04? Although the public exploit does not (yet) work with PHP 5, it is still affected. Debian Jessie already released an update on the weekend for PHP 5.6 for example.

Thanks again

Revision history for this message
Alex Murray (alexmurray) wrote :

@mig5 - php5 is covered by 14.04 ESM - see https://wiki.ubuntu.com/SecurityTeam/ESM/14.04 - so there will be a corresponding release for this.

Revision history for this message
Simon Déziel (sdeziel) wrote :

https://usn.ubuntu.com/4166-2/ provided the fix for 14.04 ESM so all supported releases are patched. As such, closing.

Changed in php-defaults (Ubuntu):
status: Confirmed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.