PublicCVE

CVE-2020-7067

HIGH7.5JSON exportCreate alert

Description

In PHP versions 7.2.x below 7.2.30, 7.3.x below 7.3.17 and 7.4.x below 7.4.5, if PHP is compiled with EBCDIC support (uncommon), urldecode() function can be made to access locations past the allocated memory, due to erroneously using signed numbers as array indexes.

CVSS breakdown

CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected products

  • PHP Group / PHP7.2.x below 7.2.30 – 7.2.x below 7.2.30
  • PHP Group / PHP7.3.x below 7.3.17 and 7.4.x below 7.4.5 – 7.3.x below 7.3.17 and 7.4.x below 7.4.5