CVE-2020-7071

NameCVE-2020-7071
DescriptionIn PHP versions 7.3.x below 7.3.26, 7.4.x below 7.4.14 and 8.0.0, when validating URL with functions like filter_var($url, FILTER_VALIDATE_URL), PHP will accept an URL with invalid password as valid URL. This may lead to functions that rely on URL being valid to mis-parse the URL and produce wrong data as components of the URL.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub advisories/code/issues, web search, more)
ReferencesDLA-2708-1, DSA-4856-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
php7.3 (PTS)buster, buster (security)7.3.31-1~deb10u1fixed
php7.4 (PTS)bullseye7.4.30-1+deb11u1fixed
bullseye (security)7.4.33-1+deb11u1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
php7.0sourcestretch7.0.33-0+deb9u11DLA-2708-1
php7.0source(unstable)(unfixed)
php7.3sourcebuster7.3.27-1~deb10u1DSA-4856-1
php7.3source(unstable)(unfixed)
php7.4source(unstable)7.4.14-1
php8.0source(unstable)8.0.1-1

Notes

Fixed in PHP 8.0.1, 7.4.14, 7.3.26
PHP Bug: https://bugs.php.net/77423

Search for package or bug name: Reporting problems