Intrusion Prevention

PHP.dns_get_record.Out.of.Bounds.Read

Description

This indicates an attack attempt to exploit an Out Of Bounds Read vulnerability in PHP.
A remote attacker could exploit this vulnerability by sending a crafted DNS response to a vulnerable server which is running a PHP application. Successful exploitation could lead to information disclosure and possible application crash.

Affected Products

PHP Group PHP 7.1.x before 7.1.26
PHP Group PHP 7.2.x before 7.2.14
PHP Group PHP 7.3.x before 7.3.2

Impact

Information Disclosure: Remote attackers can gain sensitive information from vulnerable systems.

Recommended Actions

Apply the most recent upgrade or patch from the vendor:
http://php.net/ChangeLog-7.php

CVE References

CVE-2019-9022