Low severity3.7NVD Advisory· Published Dec 23, 2019· Updated Jun 17, 2026
CVE-2019-11046
CVE-2019-11046
Description
In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP bcmath extension functions on some systems, including Windows, can be tricked into reading beyond the allocated space by supplying it with string containing characters that are identified as numeric by the OS but aren't ASCII numbers. This can read to disclosure of the content of some memory locations.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
46cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:-:*:*:*+ 5 more
- cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:-:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
- Range: <7.2.26, <7.3.13, <7.4.0
- osv-coords28 versionspkg:rpm/opensuse/php7&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/php7&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/php7&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/php7-test&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/php8&distro=openSUSE%20Tumbleweedpkg:rpm/suse/php5&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2012pkg:rpm/suse/php5&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP4pkg:rpm/suse/php53&distro=SUSE%20Linux%20Enterprise%20Point%20of%20Sale%2011%20SP3pkg:rpm/suse/php53&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-LTSSpkg:rpm/suse/php7&distro=SUSE%20Enterprise%20Storage%206pkg:rpm/suse/php7&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOSpkg:rpm/suse/php7&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/php7&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/php7&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/php7&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015pkg:rpm/suse/php7&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2012pkg:rpm/suse/php7&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2015pkg:rpm/suse/php7&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2015%20SP1pkg:rpm/suse/php7&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-BCLpkg:rpm/suse/php7&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-LTSSpkg:rpm/suse/php7&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSSpkg:rpm/suse/php7&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015pkg:rpm/suse/php7&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP1pkg:rpm/suse/php7&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP4pkg:rpm/suse/php7&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/suse/php72&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2012pkg:rpm/suse/php72&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP4pkg:rpm/suse/php72&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5
< 7.2.5-lp151.6.19.2+ 27 more
- (no CPE)range: < 7.2.5-lp151.6.19.2
- (no CPE)range: < 7.2.34-150000.4.103.1
- (no CPE)range: < 7.4.24-1.1
- (no CPE)range: < 7.2.5-lp151.6.19.2
- (no CPE)range: < 8.0.11-1.1
- (no CPE)range: < 5.5.14-109.68.1
- (no CPE)range: < 5.5.14-109.68.1
- (no CPE)range: < 5.3.17-112.79.1
- (no CPE)range: < 5.3.17-112.79.1
- (no CPE)range: < 7.2.34-150000.4.103.1
- (no CPE)range: < 7.2.34-150000.4.103.1
- (no CPE)range: < 7.2.34-150000.4.103.1
- (no CPE)range: < 7.2.34-150000.4.103.1
- (no CPE)range: < 7.2.34-150000.4.103.1
- (no CPE)range: < 7.2.5-4.49.1
- (no CPE)range: < 7.0.7-50.91.1
- (no CPE)range: < 7.2.5-4.49.1
- (no CPE)range: < 7.2.5-4.49.1
- (no CPE)range: < 7.2.34-150000.4.103.1
- (no CPE)range: < 7.2.34-150000.4.103.1
- (no CPE)range: < 7.2.34-150000.4.103.1
- (no CPE)range: < 7.2.34-150000.4.103.1
- (no CPE)range: < 7.2.34-150000.4.103.1
- (no CPE)range: < 7.0.7-50.91.1
- (no CPE)range: < 7.0.7-50.91.1
- (no CPE)range: < 7.2.5-1.32.1
- (no CPE)range: < 7.2.5-1.32.1
- (no CPE)range: < 7.2.5-1.32.1
Patches
Vulnerability mechanics
References
14- bugs.php.net/bug.phpnvdMailing ListPatchVendor Advisory
- lists.opensuse.org/opensuse-security-announce/2020-01/msg00036.htmlnvdThird Party Advisory
- lists.debian.org/debian-lts-announce/2019/12/msg00034.htmlnvdMailing ListThird Party Advisory
- seclists.org/bugtraq/2020/Feb/27nvdMailing ListThird Party Advisory
- seclists.org/bugtraq/2020/Feb/31nvdMailing ListThird Party Advisory
- seclists.org/bugtraq/2021/Jan/3nvdMailing ListThird Party Advisory
- security.netapp.com/advisory/ntap-20200103-0002/nvdThird Party Advisory
- usn.ubuntu.com/4239-1/nvdThird Party Advisory
- www.debian.org/security/2020/dsa-4626nvdThird Party Advisory
- www.debian.org/security/2020/dsa-4628nvdThird Party Advisory
- www.tenable.com/security/tns-2021-14nvdThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N7GCOAE6KVHYJ3UQ4KLPLTGSLX6IRVRN/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XWRQPYXVG43Q7DXMXH6UVWMKWGUW552F/nvd
- support.f5.com/csp/article/K48866433nvd
News mentions
0No linked articles in our index yet.