First published: Tue Sep 29 2020(Updated: )
Fixed bug (Wrong ciphertext/tag in AES-CCM encryption for a 12 bytes IV). (CVE-2020-7069)
Credit: security@php.net
Affected Software | Affected Version | How to fix |
---|---|---|
debian/php7.4 | 7.4.33-1+deb11u5 7.4.33-1+deb11u7 | |
PHP | <7.2.34 | 7.2.34 |
PHP | >=7.2.0<7.2.34 | |
PHP | >=7.3.0<7.3.23 | |
PHP | >=7.4.0<7.4.11 | |
Red Hat Fedora | =31 | |
Red Hat Fedora | =32 | |
Red Hat Fedora | =33 | |
Debian Linux | =10.0 | |
SUSE Linux | =15.1 | |
SUSE Linux | =15.2 | |
Ubuntu | =12.04 | |
Ubuntu | =14.04 | |
Ubuntu | =16.04 | |
Ubuntu | =18.04 | |
Ubuntu | =20.04 | |
IBM Data ONTAP | ||
Oracle Communications Diameter Signaling Router | >=8.0.0<=8.5.0 | |
Tenable.sc | <5.19.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-7069.
The title of the vulnerability is Fixed bug (Wrong ciphertext/tag in AES-CCM encryption for a 12 bytes IV).
The severity of CVE-2020-7069 is medium, with a CVSS score of 6.5.
PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23, and 7.4.x below 7.4.11 are affected by CVE-2020-7069.
To fix the CVE-2020-7069 vulnerability, update PHP to version 7.2.34, 7.3.23, or 7.4.11 depending on your PHP version.