USN-4330-2: PHP vulnerabilities
USN-4330-1 fixed vulnerabilities in PHP. This update provides the corresponding update for Ubuntu 20.04 LTS. Original advisory details: It was discovered that PHP incorrectly handled certain EXIF files. An attacker could possibly use this issue to access sensitive information or cause a crash. (CVE-2020-7064) It was discovered that PHP incorrectly handled certain UTF strings. An attacker could possibly use this issue to cause a crash or execute arbitrary code. (CVE-2020-7065) It was discovered that PHP incorrectly handled certain URLs. An attacker could possibly use this issue to expose sensitive information. (CVE-2020-7066)
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this advisory?
The vulnerability ID of this advisory is USN-4330-2.
What vulnerabilities does this advisory address?
This advisory addresses vulnerabilities in PHP.
Which versions of PHP are affected?
Versions up to and including 7.4.3-4ubuntu1.1 of PHP are affected.
What is the severity of the vulnerabilities?
The severity of the vulnerabilities is not specified in the advisory.
How can I fix the vulnerabilities?
To fix the vulnerabilities, update the affected software to version 7.4.3-4ubuntu1.1 or later.