Collected research
PHP-FPM RCE(CVE-2019-11043)
An analysis and thought about recently PHP-FPM RCE (CVE-2019-11043)
A newline in the URI makes nginx pass an empty PATH_INFO to PHP-FPM, so a pointer calculation underflows and writes a null byte before the buffer, corrupting the FastCGI environment allocator. A following putenv then overwrites a hash-colliding fake request header with PHP_VALUE, letting an unauthenticated attacker set php.ini directives and run commands.
Record
- Document
- An analysis and thought about recently PHP-FPM RCE (CVE-2019-11043)
- Researcher
- Orange Tsai
- Published by
- Orange Tsai
- Date
- Topic
- Server
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Orange Tsai, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .