When using fgetss() function to read data with stripping tags, in PHP versions 7.2.x below 7.2.27, 7.3.x below 7.3.14 and 7.4.x below 7.4.2 it is possible to supply data that will cause this function to read past the allocated buffer. This may lead to information disclosure or crash.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2124-1 | php5 security update |
Debian DSA |
DSA-4626-1 | php7.3 security update |
Debian DSA |
DSA-4628-1 | php7.0 security update |
EUVD |
EUVD-2020-28193 | When using fgetss() function to read data with stripping tags, in PHP versions 7.2.x below 7.2.27, 7.3.x below 7.3.14 and 7.4.x below 7.4.2 it is possible to supply data that will cause this function to read past the allocated buffer. This may lead to information disclosure or crash. |
Ubuntu USN |
USN-4279-1 | PHP vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
Usage of fgetss() has been DEPRECATED as of PHP 7.3.0. Please use strip_tags() or other means sanitizing HTML code.
References
History
No history.
Status: PUBLISHED
Assigner: php
Published:
Updated: 2024-09-17T02:37:14.052Z
Reserved: 2020-01-15T00:00:00
Link: CVE-2020-7059
No data.
Status : Modified
Published: 2020-02-10T08:15:12.673
Modified: 2024-11-21T05:36:35.167
Link: CVE-2020-7059
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN