In PHP versions 7.2.x below 7.2.30, 7.3.x below 7.3.17 and 7.4.x below 7.4.5, if PHP is compiled with EBCDIC support (uncommon), urldecode() function can be made to access locations past the allocated memory, due to erroneously using signed numbers as array indexes.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: php

Published: 2020-04-14T00:00:00

Updated: 2021-07-22T17:07:31

Reserved: 2020-01-15T00:00:00


Link: CVE-2020-7067

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-04-27T21:15:14.593

Modified: 2022-05-16T19:57:47.077


Link: CVE-2020-7067

JSON object: View

cve-icon Redhat Information

No data.