In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when AES-CCM mode is used with openssl_encrypt() function with 12 bytes IV, only first 7 bytes of the IV is actually used. This can lead to both decreased security and incorrect encryption data.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-4856-1 | php7.3 security update |
EUVD |
EUVD-2020-28203 | In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when AES-CCM mode is used with openssl_encrypt() function with 12 bytes IV, only first 7 bytes of the IV is actually used. This can lead to both decreased security and incorrect encryption data. |
Ubuntu USN |
USN-4583-1 | PHP vulnerabilities |
Ubuntu USN |
USN-4583-2 | PHP vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: php
Published:
Updated: 2024-09-17T04:04:37.418Z
Reserved: 2020-01-15T00:00:00
Link: CVE-2020-7069
No data.
Status : Modified
Published: 2020-10-02T15:15:12.670
Modified: 2024-11-21T05:36:36.820
Link: CVE-2020-7069
OpenCVE Enrichment
No data.
Debian DSA
EUVD
Ubuntu USN