CVE-2020-7061

Severity CVSS v4.0:
Pending analysis
Type:
CWE-125 Out-of-bounds Read
Publication date:
27/02/2020
Last modified:
16/05/2022

Description

In PHP versions 7.3.x below 7.3.15 and 7.4.x below 7.4.3, while extracting PHAR files on Windows using phar extension, certain content inside PHAR file could lead to one-byte read past the allocated buffer. This could potentially lead to information disclosure or crash.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:php:php:*:*:*:*:*:*:*:* 7.2.0 (including) 7.2.27 (including)
cpe:2.3:a:php:php:*:*:*:*:*:*:*:* 7.3.0 (including) 7.3.14 (including)
cpe:2.3:a:php:php:*:*:*:*:*:*:*:* 7.4.0 (including) 7.4.2 (including)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:tenable:tenable.sc:*:*:*:*:*:*:*:* 5.19.0 (excluding)