CVE-2020-7071

NameCVE-2020-7071
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
php7.0 (PTS)stretch7.0.33-0+deb9u8vulnerable
stretch (security)7.0.33-0+deb9u10vulnerable
php7.3 (PTS)buster, buster (security)7.3.19-1~deb10u1vulnerable
php7.4 (PTS)bullseye, sid7.4.11-1vulnerable
php8.0 (PTS)bullseye, sid8.0.1-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
php7.0source(unstable)(unfixed)
php7.3source(unstable)(unfixed)
php7.4source(unstable)(unfixed)
php8.0source(unstable)8.0.1-1

Notes

[stretch] - php7.0 <postponed> (Minor issue, can be fixed in next release.)
Fixed in PHP 8.0.1, 7.4.14, 7.3.26
PHP Bug: https://bugs.php.net/77423

Search for package or bug name: Reporting problems