Security Advisory

CVE-2020-7067

7.5
HIGH

Vulnerability Description

In PHP versions 7.2.x below 7.2.30, 7.3.x below 7.3.17 and 7.4.x below 7.4.5, if PHP is compiled with EBCDIC support (uncommon), urldecode() function can be made to access locations past the allocated memory, due to erroneously using signed numbers as array indexes.
Published Date April 27, 2020
Official Source NIST NVD Advisory