CVE-2020-7060
global buffer-overflow in mbfl_filt_conv_big5_wchar
9.1
CRITICAL
CVSS 3.1
EPSS 6.4%
Description
When using certain mbstring functions to convert multibyte encodings, in PHP versions 7.2.x below 7.2.27, 7.3.x below 7.3.14 and 7.4.x below 7.4.2 it is possible to supply data that will cause function mbfl_filt_conv_big5_wchar to read past the allocated buffer. This may lead to information disclosure or crash.
How to fix CVE-2020-7060
To remediate CVE-2020-7060, upgrade the affected package to a fixed version below.
- —upgrade to 7.2.27 or later
- —upgrade to 7.2.27 or later
- —upgrade to 7.2.27 or later
- —upgrade to 7.4.2-7 or later
Is CVE-2020-7060 being exploited?
Moderate — EPSS is 6.4%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (4)
- >= 7.2.0, < 7.2.27, >= 7.3.0, < 7.3.14, >= 7.4.0, < 7.4.2
- >= 7.2.0, < 7.2.27, >= 7.3.0, < 7.3.14, >= 7.4.0, < 7.4.2
- >= 7.2.0, < 7.2.27, >= 7.3.0, < 7.3.14, >= 7.4.0, < 7.4.2
- from 0, < 7.4.2-7
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H |