In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.
                
            Metrics
Affected Vendors & Products
References
        History
                    Wed, 22 Oct 2025 00:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References |  | 
Tue, 21 Oct 2025 20:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References |  | 
Tue, 21 Oct 2025 19:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References |  | 
Fri, 07 Feb 2025 14:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | kev 
 
 | 
Wed, 14 Aug 2024 00:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References |  | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: php
Published: 2019-10-28T14:19:04.252Z
Updated: 2025-10-21T23:45:28.408Z
Reserved: 2019-04-09T00:00:00.000Z
Link: CVE-2019-11043
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-08-04T22:40:16.064Z
 NVD
                        NVD
                    Status : Modified
Published: 2019-10-28T15:15:13.863
Modified: 2025-10-22T00:16:33.110
Link: CVE-2019-11043
 Redhat
                        Redhat