Lucene search

K
prionPRIOn knowledge basePRION:CVE-2019-11044
HistoryDec 23, 2019 - 3:15 a.m.

Design/Logic Flaw

2019-12-2303:15:00
PRIOn knowledge base
www.prio-n.com
7

7.5 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

54.8%

In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 on Windows, PHP link() function accepts filenames with embedded \0 byte and treats them as terminating at that byte. This could lead to security vulnerabilities, e.g. in applications checking paths that the code is allowed to access.

7.5 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

54.8%