CVE-2019-9025
moderate-risk
Published 2019-02-22
An issue was discovered in PHP 7.3.x before 7.3.1. An invalid multibyte string supplied as an argument to the mb_split() function in ext/mbstring/php_mbregex.c can cause PHP to execute memcpy() with a negative argument, which could read and write past buffers allocated for the data.
Do I need to act?
~
1.7% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
+
Fix available
Upgrade to: b51be55fe5488a090f6b12200987f4c7afe8cfd3
9
CVSS 9.8/10
Critical
NETWORK
/ LOW complexity
Affected Products (2)
References (4)
Third Party Advisory
https://security.netapp.com/advisory/ntap-20190321-0001/
Third Party Advisory
https://security.netapp.com/advisory/ntap-20190321-0001/
43
/ 100
moderate-risk
Severity
32/34 · Critical
Exploitability
4/34 · Minimal
Exposure
7/34 · Low