Lucene search

K
ubuntucveUbuntu.comUB:CVE-2020-7064
HistoryApr 01, 2020 - 12:00 a.m.

CVE-2020-7064

2020-04-0100:00:00
ubuntu.com
ubuntu.com
43

5.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:N/A:P

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L

0.004 Low

EPSS

Percentile

72.3%

In PHP versions 7.2.x below 7.2.9, 7.3.x below 7.3.16 and 7.4.x below
7.4.4, while parsing EXIF data with exif_read_data() function, it is
possible for malicious data to cause PHP to read one byte of uninitialized
memory. This could potentially lead to information disclosure or crash.

Bugs

Notes

Author Note
sbeattie PEAR issues should go against php-pear as of xenial
OSVersionArchitecturePackageVersionFilename
ubuntu14.04noarchphp5< 5.5.9+dfsg-1ubuntu4.29+esm11UNKNOWN
ubuntu16.04noarchphp7.0< 7.0.33-0ubuntu0.16.04.14UNKNOWN
ubuntu18.04noarchphp7.2< 7.2.24-0ubuntu0.18.04.4UNKNOWN
ubuntu19.10noarchphp7.3< 7.3.11-0ubuntu0.19.10.4UNKNOWN
ubuntu20.04noarchphp7.4< 7.4.3-4ubuntu1.1UNKNOWN

5.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:N/A:P

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L

0.004 Low

EPSS

Percentile

72.3%