Aller au contenu

Fiche vulnérabilité

CVE-2020-7067 : faille élevée php php (CVSS 7.5)

Description

In PHP versions 7.2.x below 7.2.30, 7.3.x below 7.3.17 and 7.4.x below 7.4.5, if PHP is compiled with EBCDIC support (uncommon), urldecode() function can be made to access locations past the allocated memory, due to erroneously using signed numbers as array indexes.

En bref

Sévérité
Élevée (CVSS 7.5)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitation active
Non signalée par la CISA
Publication
27 avr. 2020
Dernière mise à jour
17 juin 2026

Produits concernés

  • php php
  • tenable tenable.sc
  • oracle communications diameter signaling router
  • debian debian linux

Références

Rechercher une autre vulnérabilité dans la base CVE