Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-7065

Опубликовано: 01 апр. 2020
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

In PHP versions 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using mb_strtolower() function with UTF-32LE encoding, certain invalid strings could cause PHP to overwrite stack-allocated buffer. This could lead to memory corruption, crashes and potentially code execution.

A vulnerability was found in PHP while using the mb_strtolower() function with UTF-32LE encoding, where certain invalid strings cause PHP to overwrite the stack-allocated buffer. This flaw leads to memory corruption, crashes, and potential code execution.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5phpNot affected
Red Hat Enterprise Linux 5php53Not affected
Red Hat Enterprise Linux 6phpNot affected
Red Hat Enterprise Linux 7phpNot affected
Red Hat Enterprise Linux 8php:7.2/phpNot affected
Red Hat Software Collectionsrh-php72-phpNot affected
Red Hat Enterprise Linux 8phpFixedRHSA-2020:366208.09.2020
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-php73-phpFixedRHSA-2020:527501.12.2020
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSrh-php73-phpFixedRHSA-2020:527501.12.2020
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSrh-php73-phpFixedRHSA-2020:527501.12.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-787
Дефект:
CWE-121
https://bugzilla.redhat.com/show_bug.cgi?id=1820627php: Using mb_strtolower() function with UTF-32LE encoding leads to potential code execution

EPSS

Процентиль: 92%
0.0878
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.4
ubuntu
около 5 лет назад

In PHP versions 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using mb_strtolower() function with UTF-32LE encoding, certain invalid strings could cause PHP to overwrite stack-allocated buffer. This could lead to memory corruption, crashes and potentially code execution.

CVSS3: 7.4
nvd
около 5 лет назад

In PHP versions 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using mb_strtolower() function with UTF-32LE encoding, certain invalid strings could cause PHP to overwrite stack-allocated buffer. This could lead to memory corruption, crashes and potentially code execution.

CVSS3: 7.4
debian
около 5 лет назад

In PHP versions 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using ...

github
около 3 лет назад

In PHP versions 7.3.x below 7.3.16 and 7.4.x below 7.4.34, while using mb_strtolower() function with UTF-32LE encoding, certain invalid strings could cause PHP to overwrite stack-allocated buffer. This could lead to memory corruption, crashes and potentially code execution.

CVSS3: 8.8
fstec
больше 5 лет назад

Уязвимость функции mb_strtolower () при использовании кодировки UTF-32LE интерпретатора языка программирования PHP, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 92%
0.0878
Низкий

8.8 High

CVSS3