First published: Mon Aug 03 2020(Updated: )
Fixed bug (Use of freed hash key in the phar_parse_zipfile function). (CVE-2020-7068)
Credit: security@php.net
Affected Software | Affected Version | How to fix |
---|---|---|
<7.2.33 | 7.2.33 | |
PHP PHP | >=7.2.0<7.2.33 | |
PHP PHP | >=7.3.0<7.3.21 | |
PHP PHP | >=7.4.0<7.4.9 | |
Debian Debian Linux | =10.0 | |
Tenable Tenable.sc | <5.19.0 | |
debian/php7.3 | 7.3.31-1~deb10u1 7.3.31-1~deb10u5 | |
debian/php7.4 | 7.4.33-1+deb11u4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-7068 is a vulnerability in PHP that allows for the use of a freed hash key in the phar_parse_zipfile function.
CVE-2020-7068 affects PHP versions up to and excluding 7.2.33.
The severity of CVE-2020-7068 is not specified.
To fix CVE-2020-7068, update PHP to version 7.2.33 or later.
More information about CVE-2020-7068 can be found in the PHP ChangeLog at https://www.php.net/ChangeLog-7.php#7.2.33.