Input validation error in PHP - CVE-2020-7066
Published: March 20, 2020
Vulnerability identifier: #VU26257
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-7066
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass certain security restrictions.
The vulnerability exists due to get_headers() PHP function silently truncates headers after receiving a NULL byte character. A remote attacker can abuse this behavior to bypass implemented security restrictions with in the application.
Affected software
PHP
Gentoo Linux
Amazon Linux AMI
Debian Linux
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Opensuse
openEuler
Fedora
Red Hat Software Collections
Tenable.sc
php7.0 (Debian package)
php7 (Alpine package)
php7.4 (Ubuntu package)
php-help
php-gmp
php-intl
php-json
php-ldap
php-mbstring
php-mysqlnd
php-odbc
php-opcache
php-pdo
php-pgsql
php-process
php-recode
php-snmp
php-soap
php-tidy
php-xml
php-xmlrpc
php-gd
php
php-bcmath
php-cli
php-common
php-dba
php-dbg
php-debuginfo
php-debugsource
php-devel
php-embedded
php-enchant
php-fpm
php7.3 (Debian package)
rh-php73-php (Red Hat package)
Gentoo Linux
Amazon Linux AMI
Debian Linux
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Opensuse
openEuler
Fedora
Red Hat Software Collections
Tenable.sc
php7.0 (Debian package)
php7 (Alpine package)
php7.4 (Ubuntu package)
php-help
php-gmp
php-intl
php-json
php-ldap
php-mbstring
php-mysqlnd
php-odbc
php-opcache
php-pdo
php-pgsql
php-process
php-recode
php-snmp
php-soap
php-tidy
php-xml
php-xmlrpc
php-gd
php
php-bcmath
php-cli
php-common
php-dba
php-dbg
php-debuginfo
php-debugsource
php-devel
php-embedded
php-enchant
php-fpm
php7.3 (Debian package)
rh-php73-php (Red Hat package)
How to mitigate CVE-2020-7066
Install updates from vendor's website.
PHP - addressed in versions 7.2.29, 7.3.16, 7.4.4
Tenable.sc - update to 5.19.0
php7.0 (Debian package) - update to 7.0.33-0+deb9u8
php7 (Alpine package) - update to 7.2.31-r0
php7.4 (Ubuntu package) - update to 7.4.3-4ubuntu1.1
php-help - update to 7.2.10-5
php-gmp - update to 7.2.10-5
php-intl - update to 7.2.10-5
php-json - update to 7.2.10-5
php-ldap - update to 7.2.10-5
php-mbstring - update to 7.2.10-5
php-mysqlnd - update to 7.2.10-5
php-odbc - update to 7.2.10-5
php-opcache - update to 7.2.10-5
php-pdo - update to 7.2.10-5
php-pgsql - update to 7.2.10-5
php-process - update to 7.2.10-5
php-recode - update to 7.2.10-5
php-snmp - update to 7.2.10-5
php-soap - update to 7.2.10-5
php-tidy - update to 7.2.10-5
php-xml - update to 7.2.10-5
php-xmlrpc - update to 7.2.10-5
php-gd - update to 7.2.10-5
php - update to 7.2.10-5
php-bcmath - update to 7.2.10-5
php-cli - update to 7.2.10-5
php-common - update to 7.2.10-5
php-dba - update to 7.2.10-5
php-dbg - update to 7.2.10-5
php-debuginfo - update to 7.2.10-5
php-debugsource - update to 7.2.10-5
php-devel - update to 7.2.10-5
php-embedded - update to 7.2.10-5
php-enchant - update to 7.2.10-5
php-fpm - update to 7.2.10-5
php - addressed in versions 7.3.16-1.fc30, 7.3.16-1.fc31, 7.4.4-1.fc32
php7.3 (Debian package) - update to 7.3.19-1~deb10u1
rh-php73-php (Red Hat package) - update to 7.3.20-1.el7
Tenable.sc - update to 5.19.0
php7.0 (Debian package) - update to 7.0.33-0+deb9u8
php7 (Alpine package) - update to 7.2.31-r0
php7.4 (Ubuntu package) - update to 7.4.3-4ubuntu1.1
php-help - update to 7.2.10-5
php-gmp - update to 7.2.10-5
php-intl - update to 7.2.10-5
php-json - update to 7.2.10-5
php-ldap - update to 7.2.10-5
php-mbstring - update to 7.2.10-5
php-mysqlnd - update to 7.2.10-5
php-odbc - update to 7.2.10-5
php-opcache - update to 7.2.10-5
php-pdo - update to 7.2.10-5
php-pgsql - update to 7.2.10-5
php-process - update to 7.2.10-5
php-recode - update to 7.2.10-5
php-snmp - update to 7.2.10-5
php-soap - update to 7.2.10-5
php-tidy - update to 7.2.10-5
php-xml - update to 7.2.10-5
php-xmlrpc - update to 7.2.10-5
php-gd - update to 7.2.10-5
php - update to 7.2.10-5
php-bcmath - update to 7.2.10-5
php-cli - update to 7.2.10-5
php-common - update to 7.2.10-5
php-dba - update to 7.2.10-5
php-dbg - update to 7.2.10-5
php-debuginfo - update to 7.2.10-5
php-debugsource - update to 7.2.10-5
php-devel - update to 7.2.10-5
php-embedded - update to 7.2.10-5
php-enchant - update to 7.2.10-5
php-fpm - update to 7.2.10-5
php - addressed in versions 7.3.16-1.fc30, 7.3.16-1.fc31, 7.4.4-1.fc32
php7.3 (Debian package) - update to 7.3.19-1~deb10u1
rh-php73-php (Red Hat package) - update to 7.3.20-1.el7
External References
Related Security Bulletins
- Multiple vulnerabilities in PHP
- Gentoo update for PHP
- Ubuntu update for PHP
- OpenSUSE Linux update for php7
- Amazon Linux AMI update for php72
- Amazon Linux AMI update for php73
- Debian update for php7.0
- Input validation error in php7 (Alpine package)
- Red Hat Software Collections 1 for RHEL 7.7 update for rh-php73-php
- Multiple vulnerabilities in Tenable.sc
- Debian update for php7.3
- openEuler 20.03 LTS update for php-7.2.10-5
- Red Hat Enterprise Linux 8 update for the php:7.3 module
- Fedora 30 update for php
- Fedora 31 update for php
- Fedora 32 update for php