[Git][security-tracker-team/security-tracker][master] Add CVE-2020-7059/php*
Salvatore Bonaccorso
carnil at debian.org
Tue Feb 4 07:15:49 GMT 2020
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
28fdce64 by Salvatore Bonaccorso at 2020-02-04T08:15:25+01:00
Add CVE-2020-7059/php*
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -3355,8 +3355,14 @@ CVE-2020-7060 [Global buffer-overflow in mbfl_filt_conv_big5_wchar function]
- php5 <removed>
NOTE: Fixed in PHP 7.4.2, 7.3.14, 7.2.27
NOTE: PHP Bug: http://bugs.php.net/79037
-CVE-2020-7059
+CVE-2020-7059 [Out of bounds read in php_strip_tags_ex]
RESERVED
+ - php7.4 <unfixed>
+ - php7.3 <unfixed>
+ - php7.0 <removed>
+ - php5 <removed>
+ NOTE: Fixed in PHP 7.4.2, 7.3.14, 7.2.27
+ NOTE: PHP Bug: https://bugs.php.net/79099
CVE-2020-7058 (** DISPUTED ** data_input.php in Cacti 1.2.8 allows remote code execut ...)
- cacti <unfixed> (unimportant)
NOTE: https://github.com/Cacti/cacti/issues/3186
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/28fdce643ada28096448abc2a1b9c4aed4a5b784
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/28fdce643ada28096448abc2a1b9c4aed4a5b784
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20200204/741f3e71/attachment.html>
More information about the debian-security-tracker-commits
mailing list