Innovate faster and cut risk with PHP experts from Zend Services.
Explore Services
See How Zend Helps Leading Hosting Providers Keep Their Managed Sites on Secure PHP
Read More
Learn PHP from PHP experts with free, on-demand, and instructor led courses.
Explore Training
Submit support requests and browse self-service resources.
Explore Support
Global buffer-overflow in mbfl_filt_conv_big5_wchar function
When using certain mbstring functions to convert multibyte encodings, in PHP versions 7.2.x below 7.2.27, 7.3.x below 7.3.14, and 7.4.x below 7.4.2, it is possible to supply data that will cause the underlying C function mbfl_filt_conv_big5_wchar to read past the allocated buffer. This may lead to information disclosure or crash.
mbfl_filt_conv_big5_wchar
Upgrade to PHP &.2.27 or higher, 7.3.14 or higher, or 7.4.2 or higher.
Direct link to CVE-2020-7060 >
< View all CVEs