7.5

CVE-2020-7062

Exploit

Null Pointer Dereference in PHP Session Upload Progress

In PHP versions 7.2.x below 7.2.28, 7.3.x below 7.3.15 and 7.4.x below 7.4.3, when using file upload functionality, if upload progress tracking is enabled, but session.upload_progress.cleanup is set to 0 (disabled), and the file upload fails, the upload procedure would try to clean up data that does not exist and encounter null pointer dereference, which would likely lead to a crash.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Php ≫ Php Version >= 7.2.0 <= 7.2.27
Php ≫ Php Version >= 7.3.0 <= 7.3.14
Php ≫ Php Version >= 7.4.0 <= 7.4.2
Opensuse ≫ Leap Version 15.1
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition -
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 19.10
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.6% 0.881
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P
PHP 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.

https://www.tenable.com/security/tns-2021-14
Third Party Advisory
https://security.gentoo.org/glsa/202003-57
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00023.html
Third Party Advisory
Mailing List
https://bugs.php.net/bug.php?id=79221
Vendor Advisory
Exploit
https://lists.debian.org/debian-lts-announce/2020/03/msg00034.html
Third Party Advisory
Mailing List
https://usn.ubuntu.com/4330-1/
Third Party Advisory
https://www.debian.org/security/2020/dsa-4717
Third Party Advisory
https://www.debian.org/security/2020/dsa-4719
Third Party Advisory