OOB read in php_strip_tags_ex
Vulnerability Description
When using fgetss() function to read data with stripping tags, in PHP versions 7.2.x below 7.2.27, 7.3.x below 7.3.14 and 7.4.x below 7.4.2 it is possible to supply data that will cause this function to read past the allocated buffer. This may lead to information disclosure or crash.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-7059
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Reported by wxhusst at gmail dot com
References
- https://seclists.org/bugtraq/2020/Feb/27
- https://www.debian.org/security/2020/dsa-4626
- https://usn.ubuntu.com/4279-1/
- https://www.debian.org/security/2020/dsa-4628
- https://seclists.org/bugtraq/2020/Feb/31
- https://lists.debian.org/debian-lts-announce/2020/02/msg00030.html
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00023.html
- https://security.gentoo.org/glsa/202003-57
- https://www.oracle.com/security-alerts/cpujul2020.html
- https://bugs.php.net/bug.php?id=79099
- https://security.netapp.com/advisory/ntap-20200221-0002/
- https://seclists.org/bugtraq/2021/Jan/3
- https://www.oracle.com/security-alerts/cpuApr2021.html
- https://www.tenable.com/security/tns-2021-14
More from PHP Group
View All →Affected Vendor
PHP Group
View all reports →