CVE-2020-7067
Summary
| CVE | CVE-2020-7067 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-04-27 21:15:00 UTC |
| Updated | 2022-05-16 19:57:00 UTC |
| Description | In PHP versions 7.2.x below 7.2.30, 7.3.x below 7.3.17 and 7.4.x below 7.4.5, if PHP is compiled with EBCDIC support (uncommon), urldecode() function can be made to access locations past the allocated memory, due to erroneously using signed numbers as array indexes. |
Risk And Classification
Problem Types: CWE-125
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 10.0 | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Application | Oracle | Communications Diameter Signaling Router | All | All | All | All |
| Application | Php | Php | All | All | All | All |
| Application | Php | Php | All | All | All | All |
| Application | Tenable | Tenable.sc | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| PHP :: Sec Bug #79465 :: OOB Read in urldecode() | CONFIRM | bugs.php.net | Exploit, Vendor Advisory |
| Debian -- Security Information -- DSA-4719-1 php7.3 | DEBIAN | www.debian.org | |
| Oracle Critical Patch Update Advisory - October 2020 | MISC | www.oracle.com | |
| CVE-2020-7067 PHP Vulnerability in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | Third Party Advisory |
| [R1] Tenable.sc 5.19.0 Fixes Multiple Third-party Vulnerabilities - Security Advisory | Tenable® | CONFIRM | www.tenable.com | |
| Debian -- Security Information -- DSA-4717-1 php7.0 | DEBIAN | www.debian.org | |
| Oracle Critical Patch Update Advisory - April 2021 | MISC | www.oracle.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: bigshaq at wearehackerone dot com