View at Official suse advisory, NVD, CVE.org · CVE detail
Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.
CVE-2019-9637 severity low: SUSE including 948 source package names (apache2-mod_php5-5.2.14-111.46.1, apache2-mod_php5-5.5.14-109.58.1, …), 1913 product×package rows across 49 product lines (SUSE CaaS Platform 4.0, SUSE Enterprise Storage 6, … (49 product lines)): Fixed 1559, Known Not Affected 354.
An issue was discovered in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. Due to the way rename() across filesystems is implemented, it is possible that file being renamed is briefly available with wrong permissions while the rename is ongoing, thus enabling unauthorized users to access the data.