CVE-2020-7067

In PHP versions 7.2.x below 7.2.30, 7.3.x below 7.3.17 and 7.4.x below 7.4.5, if PHP is compiled with EBCDIC support (uncommon), urldecode() function can be made to access locations past the allocated memory, due to erroneously using signed numbers as array indexes.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:tenable:tenable.sc:*:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:a:oracle:communications_diameter_signaling_router:*:*:*:*:*:*:*:*

Configuration 4 (hide)

OR cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

History

21 Nov 2024, 05:36

Type Values Removed Values Added
References () https://bugs.php.net/bug.php?id=79465 - Exploit, Vendor Advisory () https://bugs.php.net/bug.php?id=79465 - Exploit, Vendor Advisory
References () https://security.netapp.com/advisory/ntap-20200504-0001/ - Third Party Advisory () https://security.netapp.com/advisory/ntap-20200504-0001/ - Third Party Advisory
References () https://www.debian.org/security/2020/dsa-4717 - Third Party Advisory () https://www.debian.org/security/2020/dsa-4717 - Third Party Advisory
References () https://www.debian.org/security/2020/dsa-4719 - Third Party Advisory () https://www.debian.org/security/2020/dsa-4719 - Third Party Advisory
References () https://www.oracle.com/security-alerts/cpuApr2021.html - Not Applicable, Third Party Advisory () https://www.oracle.com/security-alerts/cpuApr2021.html - Not Applicable, Third Party Advisory
References () https://www.oracle.com/security-alerts/cpuoct2020.html - Third Party Advisory () https://www.oracle.com/security-alerts/cpuoct2020.html - Third Party Advisory
References () https://www.tenable.com/security/tns-2021-14 - Patch, Third Party Advisory () https://www.tenable.com/security/tns-2021-14 - Patch, Third Party Advisory

Information

Published : 2020-04-27 21:15

Updated : 2024-11-21 05:36


NVD link : CVE-2020-7067

Mitre link : CVE-2020-7067

CVE.ORG link : CVE-2020-7067


JSON object : View

Products Affected

php

  • php

oracle

  • communications_diameter_signaling_router

tenable

  • tenable.sc

debian

  • debian_linux
CWE
CWE-125

Out-of-bounds Read

CWE-196

Unsigned to Signed Conversion Error