Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-7068

Опубликовано: 09 сент. 2020
Источник: debian
EPSS Низкий

Описание

In PHP versions 7.2.x below 7.2.33, 7.3.x below 7.3.21 and 7.4.x below 7.4.9, while processing PHAR files using phar extension, phar_parse_zipfile could be tricked into accessing freed memory, which could lead to a crash or information disclosure.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
php7.4fixed7.4.9-1package
php7.3removedpackage
php7.0removedpackage

Примечания

  • Fixed in PHP 7.4.9, 7.3.21, 7.2.33

  • PHP Bug: https://bugs.php.net/79797

  • https://git.php.net/?p=php-src.git;a=commit;h=7355ab81763a3d6a04ac11660e6a16d58838d187

EPSS

Процентиль: 78%
0.01156
Низкий

Связанные уязвимости

CVSS3: 4.8
ubuntu
почти 5 лет назад

In PHP versions 7.2.x below 7.2.33, 7.3.x below 7.3.21 and 7.4.x below 7.4.9, while processing PHAR files using phar extension, phar_parse_zipfile could be tricked into accessing freed memory, which could lead to a crash or information disclosure.

CVSS3: 3.6
redhat
почти 5 лет назад

In PHP versions 7.2.x below 7.2.33, 7.3.x below 7.3.21 and 7.4.x below 7.4.9, while processing PHAR files using phar extension, phar_parse_zipfile could be tricked into accessing freed memory, which could lead to a crash or information disclosure.

CVSS3: 4.8
nvd
почти 5 лет назад

In PHP versions 7.2.x below 7.2.33, 7.3.x below 7.3.21 and 7.4.x below 7.4.9, while processing PHAR files using phar extension, phar_parse_zipfile could be tricked into accessing freed memory, which could lead to a crash or information disclosure.

suse-cvrf
почти 5 лет назад

Security update for php7

suse-cvrf
почти 5 лет назад

Security update for php7

EPSS

Процентиль: 78%
0.01156
Низкий