Beveiligingsadvies

CVE-2020-7067

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2020-04-27 20:38:39
Laatst bijgewerkt 2024-09-17 02:21:12
Toegewezen door php
CVSS-score 7.5
Status PUBLISHED

Beschrijving

In PHP versions 7.2.x below 7.2.30, 7.3.x below 7.3.17 and 7.4.x below 7.4.5, if PHP is compiled with EBCDIC support (uncommon), urldecode() function can be made to access locations past the allocated memory, due to erroneously using signed numbers as array indexes.