Risk | Medium |
Patch available | YES |
Number of vulnerabilities | 1 |
CVE-ID | CVE-2020-7067 |
CWE-ID | CWE-125 |
Exploitation vector | Network |
Public exploit | N/A |
Vulnerable software Subscribe |
php7 (Alpine package) Operating systems & Components / Operating system package or component |
Vendor | Alpine Linux Development Team |
Security Bulletin
This security bulletin contains one medium risk vulnerability.
EUVDB-ID: #VU26979
Risk: Medium
CVSSv3.1: 6.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C]
CVE-ID: CVE-2020-7067
CWE-ID:
CWE-125 - Out-of-bounds read
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition when processing untrusted input passed to urldecode()
PHP function. A remote attacker can send specially crafted data to the application that uses the affected function and gain access to sensitive information on the system
Install update from vendor's website.
Vulnerable software versionsphp7 (Alpine package): 7.2.5-r0 - 7.3.16-r2
CPE2.3http://git.alpinelinux.org/aports/commit/?id=70c5111c08c96861682fc21db445c066f5d9e328
http://git.alpinelinux.org/aports/commit/?id=2aeaa29518d294e2e60944601ad49cf63a5186f1
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.