Description
In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
None
Exploits & proofs of concept
- exploit-dbPHP-FPM - Underflow Remote Code Execution (Metasploit)by Metasploit
- exploit-dbPHP-FPM + Nginx - Remote Code Executionby Emil Lerner
- nucleiPHP-FPM Path Info Buffer Underflow - Remote Code Executionby Prasath from Securin Labs (https://securin.io)
References
- MISChttps://github.com/neex/phuip-fpizdam
- MISChttps://bugs.php.net/bug.php?id=78599
- VENDOR_ADVISORYhttps://usn.ubuntu.com/4166-1/
- VENDOR_ADVISORYhttps://www.debian.org/security/2019/dsa-4552
- VENDOR_ADVISORYhttps://www.debian.org/security/2019/dsa-4553
- VENDOR_ADVISORYhttps://usn.ubuntu.com/4166-2/
- MISChttps://support.f5.com/csp/article/K75408500?utm_source=f5support&%3Butm_medium=RSS
- MAILING_LISThttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T62LF4ZWVV7OMMIZFO6IFO5QLZKK7YRD/
- MISChttps://security.netapp.com/advisory/ntap-20191031-0003/
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2019:3286
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2019:3287
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2019:3299
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2019:3300
- MAILING_LISThttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3W23TP6X4H7LB645FYZLUPNIRD5W3EPU/
- MAILING_LISThttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FSNBUSPKMLUHHOADROKNG5GDWDCRHT5M/
- MAILING_LISThttp://lists.opensuse.org/opensuse-security-announce/2019-11/msg00011.html
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2019:3724
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2019:3735
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2019:3736
- MISChttps://www.synology.com/security/advisory/Synology_SA_19_36
- MAILING_LISThttp://lists.opensuse.org/opensuse-security-announce/2019-11/msg00014.html
- VENDOR_ADVISORYhttps://support.apple.com/kb/HT210919
- MAILING_LISThttps://seclists.org/bugtraq/2020/Jan/44
- MAILING_LISThttp://seclists.org/fulldisclosure/2020/Jan/40
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2020:0322
- EXPLOIThttp://packetstormsecurity.com/files/156642/PHP-FPM-7.x-Remote-Code-Execution.html
- MISChttps://www.tenable.com/security/tns-2021-14
Updated 44m ago · 8 sources