| ID |
CVE-2020-7068
|
| Sažetak |
In PHP versions 7.2.x below 7.2.33, 7.3.x below 7.3.21 and 7.4.x below 7.4.9, while processing PHAR files using phar extension, phar_parse_zipfile could be tricked into accessing freed memory, which could lead to a crash or information disclosure. |
| Reference |
|
| CVSS |
| Base: | 3.3 |
| Impact: | 4.9 |
| Exploitability: | 3.4 |
|
| Pristup |
| Vektor | Složenost | Autentikacija |
| LOCAL |
MEDIUM |
NONE |
|
| Impact |
| Povjerljivost | Cjelovitost | Dostupnost |
| PARTIAL |
NONE |
PARTIAL |
|
| CVSS vektor |
AV:L/AC:M/Au:N/C:P/I:N/A:P |
| Zadnje važnije ažuriranje |
01-07-2022 - 12:18 |
| Objavljeno |
09-09-2020 - 18:15 |