CVE-2020-7065
by using mb_strtolower() function with UTF-32LE encoding leads to potential code execution
| Publication Date | 2020-04-01 |
|---|---|
| Severity | High |
| Type | Remote Code Execution |
| Affected PHP Versions |
|
| Fixed Product Versions |
|
CVE Details
In PHP versions 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using the mb_strtolower() function with UTF-32LE encoding, certain invalid strings could cause PHP to overwrite a stack-allocated buffer. This could lead to memory corruption, crashes, and potentially code execution.
Recommendations
Upgrade to 7.3.16 or above, or 7.4.4 or above.