SynopsisThe version of PHP running on the remote web server is affected by multiple vulnerabilities.
DescriptionAccording to its banner, the version of PHP running on the remote web server is 7.2.x prior to 7.2.29. It is, therefore, affected by multiple vulnerabilities:
- A NULL pointer de-reference flaw exists in PHP's Exif component due to its implementation attempting to use uninitialized bytes. An unauthenticated, remote attacker can exploit this to cause a denial of service condition when the application attempts to read or write memory with a NULL pointer. (CVE-2020-7064)
- An information disclosure vulnerability exists in PHP due to the `get_headers` function silently truncating anything it receives, after a null byte. An unauthenticated, remote attacker can exploit this, by supplying URLs containing a null byte, to disclose potentially sensitive information.
SolutionUpgrade to PHP version 7.2.29 or later.