CVE-2020-7063

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

In PHP versions 7.2.x below 7.2.28, 7.3.x below 7.3.15 and 7.4.x below 7.4.3, when creating PHAR archive using PharData::buildFromIterator() function, the files are added with default permissions (0666, or all access) even if the original files on the filesystem were with more restrictive permissions. This may result in files having more lax permissions than intended when such archive is extracted.

References

https://bugs.php.net/bug.php?id=79082

http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00023.html

https://security.gentoo.org/glsa/202003-57

https://lists.debian.org/debian-lts-announce/2020/03/msg00034.html

https://usn.ubuntu.com/4330-1/

https://www.debian.org/security/2020/dsa-4717

https://www.debian.org/security/2020/dsa-4719

Details

Source: MITRE

Published: 2020-02-27

Updated: 2021-07-22

Type: CWE-281

Risk Information

CVSS v2

Base Score: 5

Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Impact Score: 2.9

Exploitability Score: 10

Severity: MEDIUM

CVSS v3

Base Score: 5.3

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Impact Score: 1.4

Exploitability Score: 3.9

Severity: MEDIUM

Vulnerable Software

Configuration 1

OR

cpe:2.3:a:php:php:*:*:*:*:*:*:*:* versions from 7.2.0 to 7.2.27 (inclusive)

cpe:2.3:a:php:php:*:*:*:*:*:*:*:* versions from 7.3.0 to 7.3.14 (inclusive)

cpe:2.3:a:php:php:*:*:*:*:*:*:*:* versions from 7.4.0 to 7.4.2 (inclusive)

Tenable Plugins

View all (26 total)

IDNameProductFamilySeverity
152986Tenable SecurityCenter < 5.19.0 Multiple Vulnerabilities (TNS-2021-14)NessusMisc.
high
151985Tenable.sc < 5.19.0 Multiple Vulnerabilities (TNS-2021-14) (deprecated)NessusMisc.
high
145957CentOS 8 : php:7.3 (CESA-2020:3662)NessusCentOS Local Security Checks
critical
142352EulerOS 2.0 SP2 : php (EulerOS-SA-2020-2384)NessusHuawei Local Security Checks
critical
140834EulerOS 2.0 SP3 : php (EulerOS-SA-2020-2067)NessusHuawei Local Security Checks
critical
140482Oracle Linux 8 : php:7.3 (ELSA-2020-3662)NessusOracle Linux Local Security Checks
critical
140396RHEL 8 : php:7.3 (RHSA-2020:3662)NessusRed Hat Local Security Checks
critical
139998EulerOS Virtualization for ARM 64 3.0.6.0 : php (EulerOS-SA-2020-1895)NessusHuawei Local Security Checks
high
139151EulerOS 2.0 SP8 : php (EulerOS-SA-2020-1821)NessusHuawei Local Security Checks
high
138225Debian DSA-4719-1 : php7.3 - security updateNessusDebian Local Security Checks
high
138106Debian DSA-4717-1 : php7.0 - security updateNessusDebian Local Security Checks
medium
135672Ubuntu 16.04 LTS / 18.04 LTS / 19.10 : PHP vulnerabilities (USN-4330-1)NessusUbuntu Local Security Checks
high
134965GLSA-202003-57 : PHP: Multiple vulnerabilitiesNessusGentoo Local Security Checks
high
134955Debian DLA-2160-1 : php5 security updateNessusDebian Local Security Checks
medium
134618openSUSE Security Update : php7 (openSUSE-2020-341)NessusSuSE Local Security Checks
critical
134573Amazon Linux AMI : php73 (ALAS-2020-1351)NessusAmazon Linux Local Security Checks
critical
134572Amazon Linux AMI : php72 (ALAS-2020-1350)NessusAmazon Linux Local Security Checks
critical
134560SUSE SLES12 Security Update : php5 (SUSE-SU-2020:0658-1)NessusSuSE Local Security Checks
medium
134441SUSE SLES12 Security Update : php72 (SUSE-SU-2020:0647-1)NessusSuSE Local Security Checks
medium
134365SUSE SLED15 / SLES15 Security Update : php7 (SUSE-SU-2020:0622-1)NessusSuSE Local Security Checks
critical
98975PHP 7.2.x < 7.2.28 Multiple VulnerabilitiesWeb Application ScanningComponent Vulnerability
critical
98974PHP 7.3.x < 7.3.15 Multiple VulnerabilitiesWeb Application ScanningComponent Vulnerability
critical
98973PHP 7.4.x < 7.4.3 Multiple VulnerabilitiesWeb Application ScanningComponent Vulnerability
critical
134162PHP 7.2.x < 7.2.28 / PHP 7.3.x < 7.3.15 / 7.4.x < 7.4.3 Multiple VulnerabilitiesNessusCGI abuses
critical
134133Fedora 30 : php (2020-4ea970ebc6)NessusFedora Local Security Checks
critical
134132Fedora 31 : php (2020-32f9a2b308)NessusFedora Local Security Checks
critical