OOB Read in urldecode()
Published Apr 27, 2020
7.5
HIGHCVSS 3.1
EPSS 4.31%
Description
In PHP versions 7.2.x below 7.2.30, 7.3.x below 7.3.17 and 7.4.x below 7.4.5, if PHP is compiled with EBCDIC support (uncommon), urldecode() function can be made to access locations past the allocated memory, due to erroneously using signed numbers as array indexes.
Affected products
-
- Version 7.2.x below 7.2.30StatusaffectedConstraints-
- Version 7.3.x below 7.3.17 and 7.4.x below 7.4.5StatusaffectedConstraints-
- Version
Configuration 1
Configuration 2
- < 5.19.0
Configuration 3
- ≥ 8.0.0.0 · ≤ 8.4.0.5
Configuration 4
- 9.0
- 10.0
No data.
Red Hat Enterprise Linux 5
php
Not affected
Red Hat Enterprise Linux 5
php53
Not affected
Red Hat Enterprise Linux 6
php
Not affected
Red Hat Enterprise Linux 7
php
Not affected
Red Hat Enterprise Linux 8
php:7.2/php
Not affected
Red Hat Enterprise Linux 8
php:7.3/php
Not affected
Red Hat Software Collections
rh-php72-php
Not affected
Red Hat Software Collections
rh-php73-php
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | php | Not affected | n/a |
| Red Hat Enterprise Linux 5 | php53 | Not affected | n/a |
| Red Hat Enterprise Linux 6 | php | Not affected | n/a |
| Red Hat Enterprise Linux 7 | php | Not affected | n/a |
| Red Hat Enterprise Linux 8 | php:7.2/php | Not affected | n/a |
| Red Hat Enterprise Linux 8 | php:7.3/php | Not affected | n/a |
| Red Hat Software Collections | rh-php72-php | Not affected | n/a |
| Red Hat Software Collections | rh-php73-php | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This affects php running only on platforms using EBCDIC encoding, as versions of Red Hat Enteprise Linux uses ASCII encoding all php versions shipped with it are not vulnerable to this flaw.
References (12)
- https://access.redhat.com/security/cve/CVE-2020-7067 Vendor Advisory
- https://bugs.php.net/bug.php?id=79465 x_refsource_CONFIRMExploitVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1827653 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-28201 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-7067
- https://security.netapp.com/advisory/ntap-20200504-0001/ x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-7067
- https://www.debian.org/security/2020/dsa-4717 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.debian.org/security/2020/dsa-4719 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.oracle.com/security-alerts/cpuApr2021.html x_refsource_MISCNot ApplicableThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.html x_refsource_MISCThird Party Advisory
- https://www.tenable.com/security/tns-2021-14 x_refsource_CONFIRMPatchThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2020-7067 | Vendor Advisory | |
| https://bugs.php.net/bug.php?id=79465 | x_refsource_CONFIRMExploitVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1827653 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-28201 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-7067 | ||
| https://security.netapp.com/advisory/ntap-20200504-0001/ | x_refsource_CONFIRMThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2020-7067 | ||
| https://www.debian.org/security/2020/dsa-4717 | vendor-advisoryx_refsource_DEBIANThird Party Advisory | |
| https://www.debian.org/security/2020/dsa-4719 | vendor-advisoryx_refsource_DEBIANThird Party Advisory | |
| https://www.oracle.com/security-alerts/cpuApr2021.html | x_refsource_MISCNot ApplicableThird Party Advisory | |
| https://www.oracle.com/security-alerts/cpuoct2020.html | x_refsource_MISCThird Party Advisory | |
| https://www.tenable.com/security/tns-2021-14 | x_refsource_CONFIRMPatchThird Party Advisory |
Change history (0)
No recorded changes yet.