CVE-2020-7071

NameCVE-2020-7071
DescriptionIn PHP versions 7.3.x below 7.3.26, 7.4.x below 7.4.14 and 8.0.0, when validating URL with functions like filter_var($url, FILTER_VALIDATE_URL), PHP will accept an URL with invalid password as valid URL. This may lead to functions that rely on URL being valid to mis-parse the URL and produce wrong data as components of the URL.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-4856-1
NVD severitymedium

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
php7.0 (PTS)stretch7.0.33-0+deb9u8vulnerable
stretch (security)7.0.33-0+deb9u10vulnerable
php7.3 (PTS)buster, buster (security)7.3.27-1~deb10u1fixed
php7.4 (PTS)bullseye7.4.15-5+deb11u1fixed
sid7.4.18-1fixed
php8.0 (PTS)sid8.0.5-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
php7.0source(unstable)(unfixed)
php7.3sourcebuster7.3.27-1~deb10u1DSA-4856-1
php7.3source(unstable)(unfixed)
php7.4source(unstable)7.4.14-1
php8.0source(unstable)8.0.1-1

Notes

[stretch] - php7.0 <postponed> (Minor issue, can be fixed in next release.)
Fixed in PHP 8.0.1, 7.4.14, 7.3.26
PHP Bug: https://bugs.php.net/77423

Search for package or bug name: Reporting problems