CVE-2019-9025

An issue was discovered in PHP 7.3.x before 7.3.1. An invalid multibyte string supplied as an argument to the mb_split() function in ext/mbstring/php_mbregex.c can cause PHP to execute memcpy() with a negative argument, which could read and write past buffers allocated for the data.
References
Configurations

Configuration 1

cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
cpe:2.3:a:netapp:storage_automation_store:-:*:*:*:*:*:*:*

Information

Published : 2019-02-22 11:29

Updated : 2021-07-21 11:39


NVD link : CVE-2019-9025

Mitre link : CVE-2019-9025

Products Affected
No products.
CWE
CWE-125

Out-of-bounds Read

CWE-787