Description
In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP bcmath extension functions on some systems, including Windows, can be tricked into reading beyond the allocated space by supplying it with string containing characters that are identified as numeric by the OS but aren't ASCII numbers. This can read to disclosure of the content of some memory locations.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2050-1 | php5 security update |
Debian DSA |
DSA-4626-1 | php7.3 security update |
Debian DSA |
DSA-4628-1 | php7.0 security update |
EUVD |
EUVD-2019-2754 | In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP bcmath extension functions on some systems, including Windows, can be tricked into reading beyond the allocated space by supplying it with string containing characters that are identified as numeric by the OS but aren't ASCII numbers. This can read to disclosure of the content of some memory locations. |
Ubuntu USN |
USN-4239-1 | PHP vulnerabilities |
References
History
Mon, 17 Aug 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tenable security Center
|
|
| CPEs | cpe:2.3:a:tenable:security_center:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Tenable securitycenter
|
Tenable security Center
|
Status: PUBLISHED
Assigner: php
Published:
Updated: 2024-09-16T17:52:45.661Z
Reserved: 2019-04-09T00:00:00.000Z
Link: CVE-2019-11046
No data.
Status : Modified
Published: 2019-12-23T03:15:11.710
Modified: 2026-08-17T14:50:49.470
Link: CVE-2019-11046
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
EUVD
Ubuntu USN