suse · CVE-2020-7068

Quick triage

Priority: medium Published: 2021-05-30 14:37:29 UTC Updated: 2025-08-14 01:45:54 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2020-7068 severity moderate: SUSE including 949 source package names (apache2-mod_php5, apache2-mod_php5-5.5.14-109.79.1, …), 2190 product×package rows across 66 product lines (SLES for SAP Applications 11 SP2, SLES for SAP Applications 11 SP3, … (66 product lines)): Fixed 1910, Known Not Affected 280.

Description:

In PHP versions 7.2.x below 7.2.33, 7.3.x below 7.3.21 and 7.4.x below 7.4.9, while processing PHAR files using phar extension, phar_parse_zipfile could be tricked into accessing freed memory, which could lead to a crash or information disclosure.

cvelogic Threat Intelligence