9.1

CVE-2020-7059

Exploit

OOB read in php_strip_tags_ex

When using fgetss() function to read data with stripping tags, in PHP versions 7.2.x below 7.2.27, 7.3.x below 7.3.14 and 7.4.x below 7.4.2 it is possible to supply data that will cause this function to read past the allocated buffer. This may lead to information disclosure or crash.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Php ≫ Php Version >= 7.2.0 < 7.2.27
Php ≫ Php Version >= 7.3.0 < 7.3.14
Php ≫ Php Version >= 7.4.0 < 7.4.2
Tenable ≫ Tenable.Sc Version < 5.19.0
Opensuse ≫ Leap Version 15.1
Debian ≫ Debian Linux Version 8.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 7.12% 0.935
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.1 3.9 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
NIST 6.4 10 4.9
AV:N/AC:L/Au:N/C:P/I:N/A:P
PHP 6.5 3.9 2.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
CWE-125 Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

https://www.oracle.com/security-alerts/cpujul2020.html
Third Party Advisory
https://www.oracle.com/security-alerts/cpuApr2021.html
Third Party Advisory
https://www.tenable.com/security/tns-2021-14
Patch
Third Party Advisory
https://usn.ubuntu.com/4279-1/
Patch
Third Party Advisory
https://security.gentoo.org/glsa/202003-57
Third Party Advisory
https://seclists.org/bugtraq/2020/Feb/27
Third Party Advisory
Mailing List
https://seclists.org/bugtraq/2020/Feb/31
Third Party Advisory
Mailing List
https://seclists.org/bugtraq/2021/Jan/3
Third Party Advisory
Mailing List
https://www.debian.org/security/2020/dsa-4626
Third Party Advisory
https://www.debian.org/security/2020/dsa-4628
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00023.html
Third Party Advisory
https://bugs.php.net/bug.php?id=79099
Vendor Advisory
Exploit
https://lists.debian.org/debian-lts-announce/2020/02/msg00030.html
Third Party Advisory
https://security.netapp.com/advisory/ntap-20200221-0002/
Third Party Advisory