CVE-2020-7063

Updated: 2024-11-22 02:17:45.233723

Description:

In PHP versions 7.2.x below 7.2.28, 7.3.x below 7.3.15 and 7.4.x below 7.4.3, when creating PHAR archive using PharData::buildFromIterator() function, the files are added with default permissions (0666, or all access) even if the original files on the filesystem were with more restrictive permissions. This may result in files having more lax permissions than intended when such archive is extracted.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x MEDIUM 5
CVSS Version 3.x MEDIUM 5.3

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

Debian 10 php 7.2 5.3 MEDIUM Needs Triage 2025-04-28 18:51:24
Debian 10 php 8.0 5.3 MEDIUM Needs Triage 2025-04-28 18:51:27
Debian 10 php 7.3 5.3 MEDIUM Needs Triage 2025-04-28 18:51:25
Debian 10 php 7.4 5.3 MEDIUM Needs Triage 2025-04-28 18:51:26
Debian 10 php 8.1 5.3 MEDIUM Needs Triage 2025-04-28 18:51:28
Debian 10 php 8.2 5.3 MEDIUM Needs Triage 2025-04-28 18:51:30
Debian 10 php 5.6 5.3 MEDIUM Already Fixed 2025-05-01 03:53:02
Debian 10 php 7.1 5.3 MEDIUM Already Fixed 2025-05-02 03:53:42
Debian 10 php 7.0 5.3 MEDIUM Already Fixed 2025-05-02 03:53:42
Debian 11 php 7.2 5.3 MEDIUM Needs Triage 2025-04-28 18:51:34
Total: 124