Описание
When using fgetss() function to read data with stripping tags, in PHP versions 7.2.x below 7.2.27, 7.3.x below 7.3.14 and 7.4.x below 7.4.2 it is possible to supply data that will cause this function to read past the allocated buffer. This may lead to information disclosure or crash.
Релиз | Статус | Примечание |
---|---|---|
bionic | DNE | |
devel | DNE | |
eoan | DNE | |
esm-infra-legacy/trusty | not-affected | 5.5.9+dfsg-1ubuntu4.29+esm10 |
precise/esm | not-affected | 5.3.10-1ubuntu3.44 |
trusty | ignored | end of standard support |
trusty/esm | released | 5.5.9+dfsg-1ubuntu4.29+esm10 |
upstream | needs-triage | |
xenial | DNE |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
bionic | DNE | |
devel | DNE | |
eoan | DNE | |
esm-infra-legacy/trusty | DNE | |
esm-infra/xenial | not-affected | 7.0.33-0ubuntu0.16.04.11 |
precise/esm | DNE | |
trusty | DNE | |
trusty/esm | DNE | |
upstream | needs-triage | |
xenial | released | 7.0.33-0ubuntu0.16.04.11 |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
bionic | released | 7.2.24-0ubuntu0.18.04.3 |
devel | DNE | |
eoan | DNE | |
esm-infra-legacy/trusty | DNE | |
esm-infra/bionic | not-affected | 7.2.24-0ubuntu0.18.04.3 |
precise/esm | DNE | |
trusty | DNE | |
trusty/esm | DNE | |
upstream | released | 7.2.27 |
xenial | DNE |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
bionic | DNE | |
devel | not-affected | 7.3.15-1 |
eoan | released | 7.3.11-0ubuntu0.19.10.3 |
esm-infra-legacy/trusty | DNE | |
precise/esm | DNE | |
trusty | DNE | |
trusty/esm | DNE | |
upstream | released | 7.3.14 |
xenial | DNE |
Показывать по
EPSS
6.4 Medium
CVSS2
6.5 Medium
CVSS3
Связанные уязвимости
When using fgetss() function to read data with stripping tags, in PHP versions 7.2.x below 7.2.27, 7.3.x below 7.3.14 and 7.4.x below 7.4.2 it is possible to supply data that will cause this function to read past the allocated buffer. This may lead to information disclosure or crash.
When using fgetss() function to read data with stripping tags, in PHP versions 7.2.x below 7.2.27, 7.3.x below 7.3.14 and 7.4.x below 7.4.2 it is possible to supply data that will cause this function to read past the allocated buffer. This may lead to information disclosure or crash.
When using fgetss() function to read data with stripping tags, in PHP ...
When using fgetss() function to read data with stripping tags, in PHP versions 7.2.x below 7.2.27, 7.3.x below 7.3.14 and 7.4.x below 7.4.2 it is possible to supply data that will cause this function to read past the allocated buffer. This may lead to information disclosure or crash.
Уязвимость функции fgetss() языка сценариев общего назначения с открытым исходным кодом PHP, связанная с чтением за границами буфера памяти, позволяющая нарушителю получить доступ к конфиденциальным данным, а также вызвать отказ в обслуживании
EPSS
6.4 Medium
CVSS2
6.5 Medium
CVSS3