CVE-2020-7059
CRITICAL9.1EPSS 2.4%OOB read in php_strip_tags_ex
Published: 2/10/2020Modified: 4/28/2026
Description
When using fgetss() function to read data with stripping tags, in PHP versions 7.2.x below 7.2.27, 7.3.x below 7.3.14 and 7.4.x below 7.4.2 it is possible to supply data that will cause this function to read past the allocated buffer. This may lead to information disclosure or crash.
Affected packages (5)
- Bitnami/libphp>= 7.2.0, < 7.2.27, >= 7.3.0, < 7.3.14, >= 7.4.0, < 7.4.2
- Bitnami/php>= 7.2.0, < 7.2.27, >= 7.3.0, < 7.3.14, >= 7.4.0, < 7.4.2
- Bitnami/php-min>= 7.2.0, < 7.2.27, >= 7.3.0, < 7.3.14, >= 7.4.0, < 7.4.2
- Debian/php5from 0, < 5.6.40+dfsg-0+deb8u9
- Debian/php7.4from 0, < 7.4.2-7
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H |
References (16)
- ADVISORYhttps://security-tracker.debian.org/tracker/CVE-2020-7059
- WEBhttp://lists.opensuse.org/opensuse-security-announce/2020-03/msg00023.html
- WEBhttps://bugs.php.net/bug.php?id=79099
- WEBhttps://lists.debian.org/debian-lts-announce/2020/02/msg00030.html
- WEBhttps://nvd.nist.gov/vuln/detail/CVE-2020-7059
- WEBhttps://seclists.org/bugtraq/2020/Feb/27
- WEBhttps://seclists.org/bugtraq/2020/Feb/31
- WEBhttps://seclists.org/bugtraq/2021/Jan/3
- WEBhttps://security.gentoo.org/glsa/202003-57
- WEBhttps://security.netapp.com/advisory/ntap-20200221-0002/
- WEBhttps://usn.ubuntu.com/4279-1/
- WEBhttps://www.debian.org/security/2020/dsa-4626
- WEBhttps://www.debian.org/security/2020/dsa-4628
- WEBhttps://www.oracle.com/security-alerts/cpuApr2021.html
- WEBhttps://www.oracle.com/security-alerts/cpujul2020.html
- WEBhttps://www.tenable.com/security/tns-2021-14