Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-7067

Опубликовано: 27 апр. 2020
Источник: debian
EPSS Низкий

Описание

In PHP versions 7.2.x below 7.2.30, 7.3.x below 7.3.17 and 7.4.x below 7.4.5, if PHP is compiled with EBCDIC support (uncommon), urldecode() function can be made to access locations past the allocated memory, due to erroneously using signed numbers as array indexes.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
php7.4fixed7.4.5-1package
php7.3removedpackage
php7.0removedpackage
php5removedpackage

Примечания

  • Fixed in PHP 7.4.5, 7.3.17

  • PHP Bug: https://bugs.php.net/79465

  • https://git.php.net/?p=php-src.git;a=commit;h=9d6bf8221b05f86ce5875832f0f646c4c1f218be

  • This only affects builds which enable EDBDIC

EPSS

Процентиль: 93%
0.09983
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 5 лет назад

In PHP versions 7.2.x below 7.2.30, 7.3.x below 7.3.17 and 7.4.x below 7.4.5, if PHP is compiled with EBCDIC support (uncommon), urldecode() function can be made to access locations past the allocated memory, due to erroneously using signed numbers as array indexes.

CVSS3: 5.9
redhat
около 5 лет назад

In PHP versions 7.2.x below 7.2.30, 7.3.x below 7.3.17 and 7.4.x below 7.4.5, if PHP is compiled with EBCDIC support (uncommon), urldecode() function can be made to access locations past the allocated memory, due to erroneously using signed numbers as array indexes.

CVSS3: 7.5
nvd
около 5 лет назад

In PHP versions 7.2.x below 7.2.30, 7.3.x below 7.3.17 and 7.4.x below 7.4.5, if PHP is compiled with EBCDIC support (uncommon), urldecode() function can be made to access locations past the allocated memory, due to erroneously using signed numbers as array indexes.

CVSS3: 7.5
github
около 3 лет назад

In PHP versions 7.2.x below 7.2.30, 7.3.x below 7.3.17 and 7.4.x below 7.4.5, if PHP is compiled with EBCDIC support (uncommon), urldecode() function can be made to access locations past the allocated memory, due to erroneously using signed numbers as array indexes.

CVSS3: 7.5
fstec
около 5 лет назад

Уязвимость функции urldecode() интерпретатора языка программирования PHP, связанная с чтением за допустимыми границами буфера данных, позволяющая нарушителю получить доступ к защищаемой информации

EPSS

Процентиль: 93%
0.09983
Низкий