Description
In PHP versions 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using mb_strtolower() function with UTF-32LE encoding, certain invalid strings could cause PHP to overwrite stack-allocated buffer. This could lead to memory corruption, crashes and potentially code execution.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-4719-1 | php7.3 security update |
EUVD |
EUVD-2020-28199 | In PHP versions 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using mb_strtolower() function with UTF-32LE encoding, certain invalid strings could cause PHP to overwrite stack-allocated buffer. This could lead to memory corruption, crashes and potentially code execution. |
Ubuntu USN |
USN-4330-1 | PHP vulnerabilities |
Ubuntu USN |
USN-4330-2 | PHP vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: php
Published:
Updated: 2024-09-17T04:25:45.769Z
Reserved: 2020-01-15T00:00:00.000Z
Link: CVE-2020-7065
No data.
Status : Modified
Published: 2020-04-01T04:15:13.943
Modified: 2024-11-21T05:36:36.200
Link: CVE-2020-7065
OpenCVE Enrichment
No data.
Debian DSA
EUVD
Ubuntu USN