suse · CVE-2019-9637

Quick triage

Priority: low Published: 2021-05-30 14:25:52 UTC Updated: 2026-03-05 06:22:01 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2019-9637 severity low: SUSE including 948 source package names (apache2-mod_php5-5.2.14-111.46.1, apache2-mod_php5-5.5.14-109.58.1, …), 1913 product×package rows across 49 product lines (SUSE CaaS Platform 4.0, SUSE Enterprise Storage 6, … (49 product lines)): Fixed 1559, Known Not Affected 354.

Description:

An issue was discovered in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. Due to the way rename() across filesystems is implemented, it is possible that file being renamed is briefly available with wrong permissions while the rename is ongoing, thus enabling unauthorized users to access the data.

cvelogic Threat Intelligence