« Volver al listado

CVE-2020-7065

Estado: ModificadaAlta (8.8)—

In PHP versions 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using mb_strtolower() function with UTF-32LE encoding, certain invalid strings could cause PHP to overwrite stack-allocated buffer. This could lead to memory corruption, crashes and potentially code execution.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (4)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-7065",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@php.net",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.4,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 2.2
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@php.net",
      "affectedData": [
        {
          "vendor": "PHP Group",
          "product": "PHP",
          "versions": [
            {
              "status": "affected",
              "version": "7.3.x",
              "lessThan": "7.3.16",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "7.4.x",
              "lessThan": "7.4.4",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-04-01T04:15:13.943",
  "references": [
    {
      "url": "https://bugs.php.net/bug.php?id=79371",
      "tags": [
        "Exploit",
        "Issue Tracking",
        "Patch",
        "Vendor Advisory"
      ],
      "source": "security@php.net"
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20200403-0001/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "security@php.net"
    },
    {
      "url": "https://usn.ubuntu.com/4330-1/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "security@php.net"
    },
    {
      "url": "https://usn.ubuntu.com/4330-2/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "security@php.net"
    },
    {
      "url": "https://www.debian.org/security/2020/dsa-4719",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "security@php.net"
    },
    {
      "url": "https://www.oracle.com/security-alerts/cpuoct2021.html",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "security@php.net"
    },
    {
      "url": "https://www.php.net/ChangeLog-7.php#7.4.4",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "security@php.net"
    },
    {
      "url": "https://www.tenable.com/security/tns-2021-14",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "security@php.net"
    },
    {
      "url": "https://bugs.php.net/bug.php?id=79371",
      "tags": [
        "Exploit",
        "Issue Tracking",
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20200403-0001/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://usn.ubuntu.com/4330-1/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://usn.ubuntu.com/4330-2/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.debian.org/security/2020/dsa-4719",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.oracle.com/security-alerts/cpuoct2021.html",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.php.net/ChangeLog-7.php#7.4.4",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.tenable.com/security/tns-2021-14",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@php.net",
      "description": [
        {
          "lang": "en",
          "value": "CWE-121"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-787"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In PHP versions 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using mb_strtolower() function with UTF-32LE encoding, certain invalid strings could cause PHP to overwrite stack-allocated buffer. This could lead to memory corruption, crashes and potentially code execution."
    },
    {
      "lang": "es",
      "value": "En PHP versiones 7.3.x por debajo de 7.3.16 y versiones 7.4.x por debajo de 7.4.4, mientras se usa la función mb_strtolower() con codificación UTF-32LE, determinadas cadenas no comprobadas pueden causar que PHP sobrescriba el búfer asignado de la pila. Esto podría conllevar a una corrupción de la memoria, bloqueos y potencialmente a una ejecución de código."
    }
  ],
  "lastModified": "2026-06-17T03:24:17.803",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:php:php:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ECF918F4-EEAF-4F96-A49A-D367D549C52B",
              "versionEndExcluding": "7.3.16",
              "versionStartIncluding": "7.3.0"
            },
            {
              "criteria": "cpe:2.3:a:php:php:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F809DF30-2CCC-4E3D-819B-75E5E0827E45",
              "versionEndExcluding": "7.4.4",
              "versionStartIncluding": "7.4.0"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "07B237A9-69A3-4A9C-9DA0-4E06BD37AE73"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8D305F7A-D159-4716-AB26-5E38BB5CD991"
            },
            {
              "criteria": "cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "815D70A8-47D3-459C-A32C-9FEACA0659D1"
            },
            {
              "criteria": "cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F7016A2A-8365-4F1A-89A2-7A19F2BCAE5B"
            },
            {
              "criteria": "cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "23A7C53F-B80F-4E6A-AFA9-58EEA84BE11D"
            },
            {
              "criteria": "cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A31C8344-3E02-4EB8-8BD8-4C84B7959624"
            },
            {
              "criteria": "cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "902B8056-9E37-443B-8905-8AA93E2447FB"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:tenable:tenable.sc:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "41DBA7C7-8084-45F6-B59D-13A9022C34DF",
              "versionEndExcluding": "5.19.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@php.net"
}