Note:
This project will be discontinued after December 13, 2021. [more]
2020-04-27
In PHP versions 7.2.x below 7.2.30, 7.3.x below 7.3.17 and 7.4.x below 7.4.5, if PHP is compiled with EBCDIC support (uncommon), urldecode() function can be made to access locations past the allocated memory, due to erroneously using signed numbers as array indexes.
Products | Debian_linux, Communications_diameter_signaling_router, Php, Tenable\.sc |
Type | Out-of-bounds Read (CWE-125) |
First patch | - None (likely due to unavailable code) |
Links |
• https://bugs.php.net/bug.php?id=79465
• https://security.netapp.com/advisory/ntap-20200504-0001/ • https://www.oracle.com/security-alerts/cpuApr2021.html • https://www.tenable.com/security/tns-2021-14 • https://www.oracle.com/security-alerts/cpuoct2020.html |