[Git][security-tracker-team/security-tracker][master] Add CVE-2020-7059/php*

Salvatore Bonaccorso carnil at debian.org
Tue Feb 4 07:15:49 GMT 2020



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
28fdce64 by Salvatore Bonaccorso at 2020-02-04T08:15:25+01:00
Add CVE-2020-7059/php*

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -3355,8 +3355,14 @@ CVE-2020-7060 [Global buffer-overflow in mbfl_filt_conv_big5_wchar function]
 	- php5 <removed>
 	NOTE: Fixed in PHP 7.4.2, 7.3.14, 7.2.27
 	NOTE: PHP Bug: http://bugs.php.net/79037
-CVE-2020-7059
+CVE-2020-7059 [Out of bounds read in php_strip_tags_ex]
 	RESERVED
+	- php7.4 <unfixed>
+	- php7.3 <unfixed>
+	- php7.0 <removed>
+	- php5 <removed>
+	NOTE: Fixed in PHP 7.4.2, 7.3.14, 7.2.27
+	NOTE: PHP Bug: https://bugs.php.net/79099
 CVE-2020-7058 (** DISPUTED ** data_input.php in Cacti 1.2.8 allows remote code execut ...)
 	- cacti <unfixed> (unimportant)
 	NOTE: https://github.com/Cacti/cacti/issues/3186



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/28fdce643ada28096448abc2a1b9c4aed4a5b784

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/28fdce643ada28096448abc2a1b9c4aed4a5b784
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20200204/741f3e71/attachment.html>


More information about the debian-security-tracker-commits mailing list