High severity7.5OSV Advisory· Published Mar 9, 2019· Updated Jun 17, 2026
CVE-2019-9637
CVE-2019-9637
Description
An issue was discovered in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. Due to the way rename() across filesystems is implemented, it is possible that file being renamed is briefly available with wrong permissions while the rename is ongoing, thus enabling unauthorized users to access the data.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
74- osv-coords62 versionspkg:rpm/opensuse/php7&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/php8&distro=openSUSE%20Tumbleweedpkg:rpm/suse/php72&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP4pkg:rpm/suse/php5&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP4pkg:rpm/suse/php53&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4pkg:rpm/suse/php7&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015pkg:rpm/suse/php7&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2015pkg:rpm/almalinux/php-clipkg:rpm/suse/php5&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP3pkg:rpm/suse/php53&distro=SUSE%20Linux%20Enterprise%20Point%20of%20Sale%2011%20SP3pkg:rpm/suse/php53&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4pkg:rpm/almalinux/libzip-toolspkg:rpm/almalinux/phppkg:rpm/almalinux/php-bcmathpkg:rpm/almalinux/php-dbgpkg:rpm/almalinux/php-gdpkg:rpm/almalinux/php-ldappkg:rpm/almalinux/php-mbstringpkg:rpm/almalinux/php-mysqlndpkg:rpm/almalinux/php-pecl-apcu-develpkg:rpm/almalinux/php-pecl-zippkg:rpm/almalinux/php-pgsqlpkg:rpm/almalinux/php-processpkg:rpm/almalinux/php-recodepkg:rpm/almalinux/php-snmppkg:rpm/almalinux/php-soappkg:rpm/suse/php7&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/php7&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/php7&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSSpkg:rpm/suse/php7&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-BCLpkg:rpm/suse/php7&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015pkg:rpm/suse/php7&distro=SUSE%20Enterprise%20Storage%206pkg:rpm/opensuse/php7&distro=openSUSE%20Leap%2015.4pkg:rpm/suse/php7&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/php7&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOSpkg:rpm/suse/php7&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-LTSSpkg:rpm/suse/php7&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP1pkg:rpm/almalinux/apcu-panelpkg:rpm/almalinux/libzippkg:rpm/almalinux/libzip-develpkg:rpm/almalinux/php-commonpkg:rpm/almalinux/php-dbapkg:rpm/almalinux/php-develpkg:rpm/almalinux/php-embeddedpkg:rpm/almalinux/php-enchantpkg:rpm/almalinux/php-fpmpkg:rpm/almalinux/php-gmppkg:rpm/almalinux/php-intlpkg:rpm/almalinux/php-jsonpkg:rpm/almalinux/php-odbcpkg:rpm/almalinux/php-opcachepkg:rpm/almalinux/php-pdopkg:rpm/almalinux/php-pearpkg:rpm/almalinux/php-pecl-apcupkg:rpm/almalinux/php-xmlpkg:rpm/almalinux/php-xmlrpcpkg:rpm/suse/php53&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4pkg:rpm/suse/php72&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2012pkg:rpm/suse/php72&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP3pkg:rpm/suse/php5&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2012pkg:rpm/opensuse/php7&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/php7&distro=openSUSE%20Leap%2015.0
< 7.4.24-1.1+ 61 more
- (no CPE)range: < 7.4.24-1.1
- (no CPE)range: < 8.0.11-1.1
- (no CPE)range: < 7.2.5-1.10.1
- (no CPE)range: < 5.5.14-109.58.1
- (no CPE)range: < 5.3.17-112.58.1
- (no CPE)range: < 7.2.5-4.32.1
- (no CPE)range: < 7.2.5-4.32.1
- (no CPE)range: < 7.2.24-1.module_el8.4.0+2228+7c76a223
- (no CPE)range: < 5.5.14-109.58.1
- (no CPE)range: < 5.3.17-112.58.1
- (no CPE)range: < 5.3.17-112.58.1
- (no CPE)range: < 1.5.1-2.module_el8.4.0+2228+7c76a223
- (no CPE)range: < 7.2.24-1.module_el8.3.0+2010+7c76a223
- (no CPE)range: < 7.2.24-1.module_el8.3.0+2010+7c76a223
- (no CPE)range: < 7.2.24-1.module_el8.3.0+2010+7c76a223
- (no CPE)range: < 7.2.24-1.module_el8.5.0+53+9945c2af
- (no CPE)range: < 7.2.24-1.module_el8.3.0+2010+7c76a223
- (no CPE)range: < 7.2.24-1.module_el8.4.0+2228+7c76a223
- (no CPE)range: < 7.2.24-1.module_el8.3.0+2010+7c76a223
- (no CPE)range: < 5.1.12-2.module_el8.5.0+53+9945c2af
- (no CPE)range: < 1.15.3-1.module_el8.5.0+53+9945c2af
- (no CPE)range: < 7.2.24-1.module_el8.4.0+2228+7c76a223
- (no CPE)range: < 7.2.24-1.module_el8.5.0+53+9945c2af
- (no CPE)range: < 7.2.24-1.module_el8.5.0+53+9945c2af
- (no CPE)range: < 7.2.24-1.module_el8.3.0+2010+7c76a223
- (no CPE)range: < 7.2.24-1.module_el8.4.0+2228+7c76a223
- (no CPE)range: < 7.2.34-150000.4.103.1
- (no CPE)range: < 7.2.34-150000.4.103.1
- (no CPE)range: < 7.2.34-150000.4.103.1
- (no CPE)range: < 7.2.34-150000.4.103.1
- (no CPE)range: < 7.2.34-150000.4.103.1
- (no CPE)range: < 7.2.34-150000.4.103.1
- (no CPE)range: < 7.2.34-150000.4.103.1
- (no CPE)range: < 7.2.34-150000.4.103.1
- (no CPE)range: < 7.2.34-150000.4.103.1
- (no CPE)range: < 7.2.34-150000.4.103.1
- (no CPE)range: < 7.2.34-150000.4.103.1
- (no CPE)range: < 5.1.12-2.module_el8.3.0+2010+7c76a223
- (no CPE)range: < 1.5.1-2.module_el8.3.0+2010+7c76a223
- (no CPE)range: < 1.5.1-2.module_el8.4.0+2228+7c76a223
- (no CPE)range: < 7.2.24-1.module_el8.4.0+2228+7c76a223
- (no CPE)range: < 7.2.24-1.module_el8.4.0+2228+7c76a223
- (no CPE)range: < 7.2.24-1.module_el8.3.0+2010+7c76a223
- (no CPE)range: < 7.2.24-1.module_el8.4.0+2228+7c76a223
- (no CPE)range: < 7.2.24-1.module_el8.4.0+2228+7c76a223
- (no CPE)range: < 7.2.24-1.module_el8.3.0+2010+7c76a223
- (no CPE)range: < 7.2.24-1.module_el8.4.0+2228+7c76a223
- (no CPE)range: < 7.2.24-1.module_el8.5.0+53+9945c2af
- (no CPE)range: < 7.2.24-1.module_el8.4.0+2228+7c76a223
- (no CPE)range: < 7.2.24-1.module_el8.5.0+53+9945c2af
- (no CPE)range: < 7.2.24-1.module_el8.5.0+53+9945c2af
- (no CPE)range: < 7.2.24-1.module_el8.4.0+2228+7c76a223
- (no CPE)range: < 1:1.10.5-9.module_el8.3.0+2010+7c76a223
- (no CPE)range: < 5.1.12-2.module_el8.5.0+53+9945c2af
- (no CPE)range: < 7.2.24-1.module_el8.4.0+2228+7c76a223
- (no CPE)range: < 7.2.24-1.module_el8.5.0+53+9945c2af
- (no CPE)range: < 5.3.17-112.58.1
- (no CPE)range: < 7.2.5-1.10.1
- (no CPE)range: < 7.2.5-1.10.1
- (no CPE)range: < 5.5.14-109.58.1
- (no CPE)range: < 7.2.5-lp151.6.3.1
- (no CPE)range: < 7.2.5-lp150.2.19.1
cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*+ 4 more
- cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:storage_automation_store:-:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
15- bugs.php.net/bug.phpnvdIssue TrackingPatchVendor Advisory
- lists.opensuse.org/opensuse-security-announce/2019-04/msg00104.htmlnvdMailing ListThird Party Advisory
- lists.debian.org/debian-lts-announce/2019/03/msg00043.htmlnvdMailing ListThird Party Advisory
- security.netapp.com/advisory/ntap-20190502-0007/nvdThird Party Advisory
- support.f5.com/csp/article/K53825211nvdThird Party Advisory
- usn.ubuntu.com/3922-1/nvdThird Party Advisory
- usn.ubuntu.com/3922-2/nvdThird Party Advisory
- usn.ubuntu.com/3922-3/nvdThird Party Advisory
- www.debian.org/security/2019/dsa-4403nvdThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2019-06/msg00012.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2019-06/msg00041.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2019-06/msg00044.htmlnvd
- access.redhat.com/errata/RHSA-2019:2519nvd
- access.redhat.com/errata/RHSA-2019:3299nvd
- www.tenable.com/security/tns-2019-07nvd
News mentions
0No linked articles in our index yet.