CVE-2020-7059

critical
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

When using fgetss() function to read data with stripping tags, in PHP versions 7.2.x below 7.2.27, 7.3.x below 7.3.14 and 7.4.x below 7.4.2 it is possible to supply data that will cause this function to read past the allocated buffer. This may lead to information disclosure or crash.

References

https://bugs.php.net/bug.php?id=79099

https://seclists.org/bugtraq/2020/Feb/27

https://www.debian.org/security/2020/dsa-4626

https://usn.ubuntu.com/4279-1/

https://seclists.org/bugtraq/2020/Feb/31

https://www.debian.org/security/2020/dsa-4628

https://security.netapp.com/advisory/ntap-20200221-0002/

https://lists.debian.org/debian-lts-announce/2020/02/msg00030.html

http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00023.html

https://security.gentoo.org/glsa/202003-57

https://www.oracle.com/security-alerts/cpujul2020.html

https://seclists.org/bugtraq/2021/Jan/3

https://www.oracle.com/security-alerts/cpuApr2021.html

Details

Source: MITRE

Published: 2020-02-10

Updated: 2021-07-22

Type: CWE-125

Risk Information

CVSS v2

Base Score: 6.4

Vector: AV:N/AC:L/Au:N/C:P/I:N/A:P

Impact Score: 4.9

Exploitability Score: 10

Severity: MEDIUM

CVSS v3

Base Score: 9.1

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Impact Score: 5.2

Exploitability Score: 3.9

Severity: CRITICAL

Tenable Plugins

View all (28 total)

IDNameProductFamilySeverity
152986Tenable SecurityCenter < 5.19.0 Multiple Vulnerabilities (TNS-2021-14)NessusMisc.
high
151985Tenable.sc < 5.19.0 Multiple Vulnerabilities (TNS-2021-14) (deprecated)NessusMisc.
high
150651SUSE SLES11 Security Update : php53 (SUSE-SU-2020:14289-1)NessusSuSE Local Security Checks
critical
145957CentOS 8 : php:7.3 (CESA-2020:3662)NessusCentOS Local Security Checks
critical
142352EulerOS 2.0 SP2 : php (EulerOS-SA-2020-2384)NessusHuawei Local Security Checks
critical
140834EulerOS 2.0 SP3 : php (EulerOS-SA-2020-2067)NessusHuawei Local Security Checks
critical
140482Oracle Linux 8 : php:7.3 (ELSA-2020-3662)NessusOracle Linux Local Security Checks
critical
140396RHEL 8 : php:7.3 (RHSA-2020:3662)NessusRed Hat Local Security Checks
critical
139998EulerOS Virtualization for ARM 64 3.0.6.0 : php (EulerOS-SA-2020-1895)NessusHuawei Local Security Checks
high
139151EulerOS 2.0 SP8 : php (EulerOS-SA-2020-1821)NessusHuawei Local Security Checks
high
134965GLSA-202003-57 : PHP: Multiple vulnerabilitiesNessusGentoo Local Security Checks
high
134618openSUSE Security Update : php7 (openSUSE-2020-341)NessusSuSE Local Security Checks
critical
134365SUSE SLED15 / SLES15 Security Update : php7 (SUSE-SU-2020:0622-1)NessusSuSE Local Security Checks
critical
134199SUSE SLES12 Security Update : php5 (SUSE-SU-2020:0522-1)NessusSuSE Local Security Checks
critical
134175Debian DLA-2124-1 : php5 security updateNessusDebian Local Security Checks
critical
134120Amazon Linux AMI : php73 (ALAS-2020-1347)NessusAmazon Linux Local Security Checks
critical
134119Amazon Linux AMI : php72 (ALAS-2020-1346)NessusAmazon Linux Local Security Checks
critical
133840Ubuntu 16.04 LTS : PHP regression (USN-4279-2)NessusUbuntu Local Security Checks
critical
133815Debian DSA-4628-1 : php7.0 - security updateNessusDebian Local Security Checks
critical
133792SUSE SLES12 Security Update : php72 (SUSE-SU-2020:0397-1)NessusSuSE Local Security Checks
critical
133764Ubuntu 16.04 LTS / 18.04 LTS / 19.10 : PHP vulnerabilities (USN-4279-1)NessusUbuntu Local Security Checks
critical
133733Debian DSA-4626-1 : php7.3 - security updateNessusDebian Local Security Checks
critical
133430Fedora 31 : php (2020-dca9810fd2)NessusFedora Local Security Checks
critical
133400PHP 7.2.x < 7.2.27 / PHP 7.3.x < 7.3.14 / 7.4.x < 7.4.2 Multiple VulnerabilitiesNessusCGI abuses
critical
133379Fedora 30 : php (2020-f9d2203f3b)NessusFedora Local Security Checks
critical
98934PHP 7.2.x < 7.2.27 Multiple VulnerabilitiesWeb Application ScanningComponent Vulnerability
critical
98933PHP 7.3.x < 7.3.14 Multiple VulnerabilitiesWeb Application ScanningComponent Vulnerability
critical
98932PHP 7.4.x < 7.4.2 Multiple VulnerabilitiesWeb Application ScanningComponent Vulnerability
critical