Vulnerability CVE-2020-7059: Information

Description

When using fgetss() function to read data with stripping tags, in PHP versions 7.2.x below 7.2.27, 7.3.x below 7.3.14 and 7.4.x below 7.4.2 it is possible to supply data that will cause this function to read past the allocated buffer. This may lead to information disclosure or crash.

Severity: CRITICAL (9.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Published: Feb. 10, 2020
Modified: July 1, 2022
Error type identifier: CWE-125

Fixed packages

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
      Start including
      7.4.0
      End excliding
      7.4.2

      cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
      Start including
      7.2.0
      End excliding
      7.2.27

      cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
      Start including
      7.3.0
      End excliding
      7.3.14

      Configuration 2

      cpe:2.3:a:tenable:tenable.sc:*:*:*:*:*:*:*:*
      End excliding
      5.19.0

      Configuration 3

      cpe:2.3:a:oracle:communications_diameter_signaling_router:*:*:*:*:*:*:*:*
      Start including
      8.0
      End including
      8.4

      Configuration 4

      cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*

      Configuration 5

      cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*