In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP DirectoryIterator class accepts filenames with embedded \0 byte and treats them as terminating at that byte. This could lead to s…
Low CVSS 3.7
Summary
In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP DirectoryIterator class accepts filenames with embedded \0 byte and treats them as terminating at that byte. This could lead to security vulnerabilities, e.g. in applications checking paths that the code is allowed to access.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
- :
- :
- :
- :
- :
Sources
- NVD DATABASE
Original Links
- http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00036.html Mailing List
- https://bugs.php.net/bug.php?id=78863 Exploit
- https://lists.debian.org/debian-lts-announce/2019/12/msg00034.html Mailing List
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N7GCOAE6KVHYJ3UQ4KLPLTGSLX6IRVRN/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XWRQPYXVG43Q7DXMXH6UVWMKWGUW552F/
- https://seclists.org/bugtraq/2020/Feb/27 Mailing List
- https://seclists.org/bugtraq/2020/Feb/31 Mailing List
- https://seclists.org/bugtraq/2021/Jan/3 Mailing List
- https://security.netapp.com/advisory/ntap-20200103-0002/ Third Party Advisory
- https://usn.ubuntu.com/4239-1/ Third Party Advisory
- https://www.debian.org/security/2020/dsa-4626 Third Party Advisory
- https://www.debian.org/security/2020/dsa-4628 Third Party Advisory
- https://www.tenable.com/security/tns-2021-14 Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00036.html Mailing List
- https://bugs.php.net/bug.php?id=78863 Exploit
- https://lists.debian.org/debian-lts-announce/2019/12/msg00034.html Mailing List
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N7GCOAE6KVHYJ3UQ4KLPLTGSLX6IRVRN/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XWRQPYXVG43Q7DXMXH6UVWMKWGUW552F/
- https://seclists.org/bugtraq/2020/Feb/27 Mailing List
- https://seclists.org/bugtraq/2020/Feb/31 Mailing List
- https://seclists.org/bugtraq/2021/Jan/3 Mailing List
- https://security.netapp.com/advisory/ntap-20200103-0002/ Third Party Advisory
- https://usn.ubuntu.com/4239-1/ Third Party Advisory
- https://www.debian.org/security/2020/dsa-4626 Third Party Advisory
- https://www.debian.org/security/2020/dsa-4628 Third Party Advisory
- https://www.tenable.com/security/tns-2021-14 Third Party Advisory
Timeline
- nvd_ingest NVD