Skip to main content
LOW

CVE-2020-7068

CVSS v3

3.6

LOW

EPSS Score

0.8 %

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

In PHP versions 7.2.x below 7.2.33, 7.3.x below 7.3.21 and 7.4.x below 7.4.9, while processing PHAR files using phar extension, phar_parse_zipfile could be tricked into accessing freed memory, which could lead to a crash or information disclosure.

Technical details

Published
2020-09-09

Frequently asked questions

What is CVE-2020-7068?

In PHP versions 7.2.x below 7.2.33, 7.3.x below 7.3.21 and 7.4.x below 7.4.9, while processing PHAR files using phar extension, phar_parse_zipfile could be tricked into accessing freed memory, which could lead to a crash or information disclosure.

Is CVE-2020-7068 actively exploited?

Active exploitation of CVE-2020-7068 has not been confirmed. The EPSS score is 0.8%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2020-7068?

CVE-2020-7068 has a CVSS v3 base score of 3.6 (LOW severity).

Is CVE-2020-7068 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key