cbcvebase.
CVE-2020-7067
published 2020-04-27

CVE-2020-7067: In PHP versions 7.2.x below 7.2.30, 7.3.x below 7.3.17 and 7.4.x below 7.4.5, if PHP is compiled with EBCDIC support (uncommon), urldecode() function can be…

high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
In PHP versions 7.2.x below 7.2.30, 7.3.x below 7.3.17 and 7.4.x below 7.4.5, if PHP is compiled with EBCDIC support (uncommon), urldecode() function can be made to access locations past the allocated memory, due to erroneously using signed numbers as array indexes.

Affected

10 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianphp7.4< php7.4 7.4.5-1 (bullseye)php7.4 7.4.5-1 (bullseye)
oraclecommunications_diameter_signaling_router8.0.0.0 – 8.4.0.5
phpphp>= 7.2.0 < 7.2.307.2.30
phpphp>= 7.3.0 < 7.3.177.3.17
phpphp>= 7.4.0 < 7.4.57.4.5
php_groupphp
php_groupphp
tenabletenable.sc< 5.19.05.19.0

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
osv7.5HIGH