Description
In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP bcmath extension functions on some systems, including Windows, can be tricked into reading beyond the allocated space by supplying it with string containing characters that are identified as numeric by the OS but aren't ASCII numbers. This can read to disclosure of the content of some memory locations.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Affected products
- Canonical / Ubuntu Linux18.04 – 18.04
- Canonical / Ubuntu Linux19.04 – 19.04
- Canonical / Ubuntu Linux19.10 – 19.10
- Canonical / Ubuntu Linux12.04 – 12.04
- Canonical / Ubuntu Linux14.04 – 14.04
- Canonical / Ubuntu Linux16.04 – 16.04
- debian / debian_linux9.0 – 9.0
- debian / debian_linux10.0 – 10.0
- debian / debian_linux8.0 – 8.0
- fedoraproject / fedora31 – 31
- fedoraproject / fedora30 – 30
- openSUSE / Leap15.1 – 15.1
- php / php7.2.0 – 7.2.26
- php / php7.4.0 – 7.4.0
- PHP Group / PHP7.2.x – 7.2.26
- PHP Group / PHP7.3.x – 7.3.13
- PHP Group / PHP7.4.x – 7.4.1
- tenable / Security Center5.19.0
References
- MISChttps://bugs.php.net/bug.php?id=78878
- MAILING_LISThttps://lists.debian.org/debian-lts-announce/2019/12/msg00034.html
- MISChttps://security.netapp.com/advisory/ntap-20200103-0002/
- MAILING_LISThttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N7GCOAE6KVHYJ3UQ4KLPLTGSLX6IRVRN/
- MAILING_LISThttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XWRQPYXVG43Q7DXMXH6UVWMKWGUW552F/
- MISChttps://support.f5.com/csp/article/K48866433?utm_source=f5support&%3Butm_medium=RSS
- VENDOR_ADVISORYhttps://usn.ubuntu.com/4239-1/
- MAILING_LISThttp://lists.opensuse.org/opensuse-security-announce/2020-01/msg00036.html
- MAILING_LISThttps://seclists.org/bugtraq/2020/Feb/27
- VENDOR_ADVISORYhttps://www.debian.org/security/2020/dsa-4626
- VENDOR_ADVISORYhttps://www.debian.org/security/2020/dsa-4628
- MAILING_LISThttps://seclists.org/bugtraq/2020/Feb/31
- MAILING_LISThttps://seclists.org/bugtraq/2021/Jan/3
- MISChttps://www.tenable.com/security/tns-2021-14
Updated 5m ago · 8 sources