PT-2020-5187 · Php+1 · Php+1

Damian Bury

·

Published

2020-04-14

·

Updated

2025-08-11

·

CVE-2020-7067

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions PHP versions 7.2.x through 7.2.29 PHP versions 7.3.x through 7.3.16 PHP versions 7.4.x through 7.4.4
Description The issue is related to the urldecode() function in PHP, which can be exploited to access memory locations past the allocated buffer due to the erroneous use of signed numbers as array indexes. This can allow a remote attacker to access protected information. The vulnerability is particularly relevant when PHP is compiled with EBCDIC support, although this is an uncommon configuration.
Recommendations For PHP versions 7.2.x through 7.2.29, update to version 7.2.30 or later. For PHP versions 7.3.x through 7.3.16, update to version 7.3.17 or later. For PHP versions 7.4.x through 7.4.4, update to version 7.4.5 or later.

Exploit

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

ALT-PU-2020-1828
ALT-PU-2020-1853
BDU:2020-05806
BIT-LIBPHP-2020-7067
BIT-PHP-2020-7067
BIT-PHP-MIN-2020-7067
CVE-2020-7067
DLA-2188-1
DSA-4717-1
DSA-4719-1
MGASA-2020-0178
OESA-2022-1556

Affected Products

Alt Linux
Php