Vulnerabilities > CVE-2020-7068 - Use After Free vulnerability in multiple products
Attack vector
LOCAL Attack complexity
HIGH Privileges required
LOW Confidentiality impact
LOW Integrity impact
NONE Availability impact
LOW Summary
In PHP versions 7.2.x below 7.2.33, 7.3.x below 7.3.21 and 7.4.x below 7.4.9, while processing PHAR files using phar extension, phar_parse_zipfile could be tricked into accessing freed memory, which could lead to a crash or information disclosure.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
References
- https://bugs.php.net/bug.php?id=79797
- https://bugs.php.net/bug.php?id=79797
- https://security.gentoo.org/glsa/202009-10
- https://security.gentoo.org/glsa/202009-10
- https://security.netapp.com/advisory/ntap-20200918-0005/
- https://security.netapp.com/advisory/ntap-20200918-0005/
- https://www.debian.org/security/2021/dsa-4856
- https://www.debian.org/security/2021/dsa-4856
- https://www.tenable.com/security/tns-2021-14
- https://www.tenable.com/security/tns-2021-14