Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-7068

Опубликовано: 06 авг. 2020
Источник: redhat
CVSS3: 3.6
EPSS Низкий

Описание

In PHP versions 7.2.x below 7.2.33, 7.3.x below 7.3.21 and 7.4.x below 7.4.9, while processing PHAR files using phar extension, phar_parse_zipfile could be tricked into accessing freed memory, which could lead to a crash or information disclosure.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5phpOut of support scope
Red Hat Enterprise Linux 5php53Out of support scope
Red Hat Enterprise Linux 6phpOut of support scope
Red Hat Enterprise Linux 7phpFix deferred
Red Hat Enterprise Linux 8php:7.2/phpFix deferred
Red Hat Enterprise Linux 8php:7.3/phpFix deferred
Red Hat Software Collectionsrh-php72-phpOut of support scope
Red Hat Enterprise Linux 8phpFixedRHSA-2021:421309.11.2021
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-php73-phpFixedRHSA-2021:299203.08.2021
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSrh-php73-phpFixedRHSA-2021:299203.08.2021

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=1868109php: Use of freed hash key in the phar_parse_zipfile function

EPSS

Процентиль: 78%
0.01156
Низкий

3.6 Low

CVSS3

Связанные уязвимости

CVSS3: 4.8
ubuntu
почти 5 лет назад

In PHP versions 7.2.x below 7.2.33, 7.3.x below 7.3.21 and 7.4.x below 7.4.9, while processing PHAR files using phar extension, phar_parse_zipfile could be tricked into accessing freed memory, which could lead to a crash or information disclosure.

CVSS3: 4.8
nvd
почти 5 лет назад

In PHP versions 7.2.x below 7.2.33, 7.3.x below 7.3.21 and 7.4.x below 7.4.9, while processing PHAR files using phar extension, phar_parse_zipfile could be tricked into accessing freed memory, which could lead to a crash or information disclosure.

CVSS3: 4.8
debian
почти 5 лет назад

In PHP versions 7.2.x below 7.2.33, 7.3.x below 7.3.21 and 7.4.x below ...

suse-cvrf
почти 5 лет назад

Security update for php7

suse-cvrf
почти 5 лет назад

Security update for php7

EPSS

Процентиль: 78%
0.01156
Низкий

3.6 Low

CVSS3