In PHP versions 7.2.x below 7.2.30, 7.3.x below 7.3.17 and 7.4.x below 7.4.5, if PHP is compiled with EBCDIC support (uncommon), urldecode() function can be made to access locations past the allocated memory, due to erroneously using signed numbers as array indexes.
2020-04-27T21:15:14.593
2024-11-21T05:36:36.513
Modified
CVSSv3.1: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | php | php | < 7.2.30 | Yes |
Application | php | php | < 7.3.17 | Yes |
Application | php | php | < 7.4.5 | Yes |
Application | tenable | tenable.sc | < 5.19.0 | Yes |
Application | oracle | communications_diameter_signaling_router | ≤ 8.4.0.5 | Yes |
Operating System | debian | debian_linux | 9.0 | Yes |
Operating System | debian | debian_linux | 10.0 | Yes |