CVE-2020-7061

MEDIUM

Php < 7.2.27 - Out-of-Bounds Read

Title source: rule
STIX 2.1

Description

In PHP versions 7.3.x below 7.3.15 and 7.4.x below 7.4.3, while extracting PHAR files on Windows using phar extension, certain content inside PHAR file could lead to one-byte read past the allocated buffer. This could potentially lead to information disclosure or crash.

References (3)

Core 3
Core References
Exploit, Vendor Advisory x_refsource_misc
https://bugs.php.net/bug.php?id=79171
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/202003-57
Patch, Third Party Advisory x_refsource_confirm
https://www.tenable.com/security/tns-2021-14

Scores

CVSS v3 6.5
EPSS 0.0277
EPSS Percentile 86.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L

Details

CWE
CWE-125
Status published
Products (2)
php/php 7.2.0 - 7.2.27
tenable/tenable.sc < 5.19.0
Published Feb 27, 2020
Tracked Since Feb 18, 2026