Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-7061

Опубликовано: 27 фев. 2020
Источник: debian
EPSS Низкий

Описание

In PHP versions 7.3.x below 7.3.15 and 7.4.x below 7.4.3, while extracting PHAR files on Windows using phar extension, certain content inside PHAR file could lead to one-byte read past the allocated buffer. This could potentially lead to information disclosure or crash.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
php7.4not-affectedpackage
php7.3not-affectedpackage
php7.0not-affectedpackage
php5not-affectedpackage

Примечания

  • Fixed in PHP 7.4.3, 7.3.15

  • PHP Bug: https://bugs.php.net/79171

EPSS

Процентиль: 84%
0.02297
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 5 лет назад

In PHP versions 7.3.x below 7.3.15 and 7.4.x below 7.4.3, while extracting PHAR files on Windows using phar extension, certain content inside PHAR file could lead to one-byte read past the allocated buffer. This could potentially lead to information disclosure or crash.

CVSS3: 9.1
redhat
больше 5 лет назад

In PHP versions 7.3.x below 7.3.15 and 7.4.x below 7.4.3, while extracting PHAR files on Windows using phar extension, certain content inside PHAR file could lead to one-byte read past the allocated buffer. This could potentially lead to information disclosure or crash.

CVSS3: 6.5
nvd
больше 5 лет назад

In PHP versions 7.3.x below 7.3.15 and 7.4.x below 7.4.3, while extracting PHAR files on Windows using phar extension, certain content inside PHAR file could lead to one-byte read past the allocated buffer. This could potentially lead to information disclosure or crash.

CVSS3: 9.1
github
около 3 лет назад

In PHP versions 7.3.x below 7.3.15 and 7.4.x below 7.4.3, while extracting PHAR files on Windows using phar extension, certain content inside PHAR file could lead to one-byte read past the allocated buffer. This could potentially lead to information disclosure or crash.

EPSS

Процентиль: 84%
0.02297
Низкий