VulnerabilityModified
CVE-2020-7065
This could lead to memory corruption, crashes and potentially code execution.
HIGH 8.8EPSS 4.88%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.88%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In PHP versions 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using mb_strtolower() function with UTF-32LE encoding, certain invalid strings could cause PHP to overwrite stack-allocated buffer. This could lead to memory corruption, crashes and potentially code execution.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 4.88% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-121, CWE-787
- Affected
- php/php · debian/debian linux · canonical/ubuntu linux · tenable/tenable.sc
- Source
- security@php.net
References
- https://bugs.php.net/bug.php?id=79371Exploit, Issue Tracking, Patch, Vendor Advisory
- https://security.netapp.com/advisory/ntap-20200403-0001/Third Party Advisory
- https://usn.ubuntu.com/4330-1/Third Party Advisory
- https://usn.ubuntu.com/4330-2/Third Party Advisory
- https://www.debian.org/security/2020/dsa-4719Third Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.htmlPatch, Third Party Advisory
- https://www.php.net/ChangeLog-7.php#7.4.4Release Notes, Vendor Advisory
- https://www.tenable.com/security/tns-2021-14Third Party Advisory
- https://bugs.php.net/bug.php?id=79371Exploit, Issue Tracking, Patch, Vendor Advisory
- https://security.netapp.com/advisory/ntap-20200403-0001/Third Party Advisory
- https://usn.ubuntu.com/4330-1/Third Party Advisory
- https://usn.ubuntu.com/4330-2/Third Party Advisory
- https://www.debian.org/security/2020/dsa-4719Third Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.htmlPatch, Third Party Advisory
- https://www.php.net/ChangeLog-7.php#7.4.4Release Notes, Vendor Advisory
- https://www.tenable.com/security/tns-2021-14Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.