VYPR
Unrated severityNVD Advisory· Published Apr 1, 2020· Updated Sep 17, 2024

mb_strtolower (UTF-32LE): stack-buffer-overflow at php_unicode_tolower_full

CVE-2020-7065

Description

In PHP versions 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using mb_strtolower() function with UTF-32LE encoding, certain invalid strings could cause PHP to overwrite stack-allocated buffer. This could lead to memory corruption, crashes and potentially code execution.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

8

News mentions

0

No linked articles in our index yet.