Lucene search

K
hackeroneBigshaqH1:852103
HistoryApr 17, 2020 - 9:39 a.m.

Internet Bug Bounty: Out-of-Bound Read in urldecode() [CVE-2020-7067]

2020-04-1709:39:51
bigshaq
hackerone.com
38

EPSS

0.017

Percentile

88.1%

Hi,
Please see: https://bugs.php.net/bug.php?id=79465&edit=2

CVE is assigned (CVE-2020-7067)
Fixed in 7.4.5 Release: https://www.php.net/ChangeLog-7.php#7.4.5

Impact

A remote attacker might leak values from the memory by crafting a malicious url-encoded string into PHP’s urldecode()