CVE-2020-7066
Summary
| CVE | CVE-2020-7066 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-04-01 04:15:00 UTC |
| Updated | 2022-05-08 23:51:00 UTC |
| Description | In PHP versions 7.2.x below 7.2.29, 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using get_headers() with user-supplied URL, if the URL contains zero (\0) character, the URL will be silently truncated at it. This may cause some software to make incorrect assumptions about the target of the get_headers() and possibly send some information to a wrong server. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 10.0 | All | All | All |
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Operating System | Opensuse | Leap | 15.1 | All | All | All |
| Application | Php | Php | All | All | All | All |
| Application | Php | Php | All | All | All | All |
| Application | Tenable | Tenable.sc | All | All | All | All |
| Application | Tenable | Tenable.sc | 5.19.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Debian -- Security Information -- DSA-4719-1 php7.3 | DEBIAN | www.debian.org | |
| March 2020 PHP Vulnerabilities in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | Third Party Advisory |
| [security-announce] openSUSE-SU-2020:0642-1: moderate: Security update f | SUSE | lists.opensuse.org | |
| [SECURITY] [DLA 2188-1] php5 security update | MLIST | lists.debian.org | Third Party Advisory |
| [R1] Tenable.sc 5.19.0 Fixes Multiple Third-party Vulnerabilities - Security Advisory | Tenable® | CONFIRM | www.tenable.com | |
| PHP :: Sec Bug #79329 :: get_headers() silently truncates after a null byte | MISC | bugs.php.net | Exploit, Issue Tracking, Patch, Vendor Advisory |
| USN-4330-2: PHP vulnerabilities | Ubuntu security notices | UBUNTU | usn.ubuntu.com | |
| Debian -- Security Information -- DSA-4717-1 php7.0 | DEBIAN | www.debian.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: 64796c6e69 at gmail dot com
Legacy QID Mappings
- 296074 Oracle Solaris 11.4 Support Repository Update (SRU) 22.69.4 Missing (CPUAPR2020)
- 501137 Alpine Linux Security Update for php7
- 752878 SUSE Enterprise Linux Security Update for php7 (SUSE-SU-2022:4067-1)
- 940250 AlmaLinux Security Update for php:7.3 (ALSA-2020:3662)
- 960421 Rocky Linux Security Update for php:7.3 (RLSA-2020:3662)