RHSA-2020:3662MediumCVSS 8.8

Red Hat Security Advisory: php:7.3 security, bug fix, and enhancement update

Published
September 8, 2020
Last Modified
August 17, 2026

🔗 CVE IDs covered (22)

📋 Description

CVE-2019-11039 — php: Out-of-bounds read due to integer overflow in iconv_mime_decode_headers() CVE-2019-11040 — php: Buffer over-read in exif_read_data() CVE-2019-11041 — php: Heap buffer over-read in exif_scan_thumbnail() CVE-2019-11042 — php: Heap buffer over-read in exif_process_user_comment() CVE-2019-11045 — php: DirectoryIterator class accepts filenames with embedded \0 byte and treats them as terminating at that byte CVE-2019-11047 — php: Information disclosure in exif_read_data() CVE-2019-11048 — php: Integer wraparounds when receiving multipart forms CVE-2019-11050 — php: Out of bounds read when parsing EXIF information CVE-2019-13224 — oniguruma: Use-after-free in onig_new_deluxe() in regext.c CVE-2019-13225 — oniguruma: NULL pointer dereference in match_at() in regexec.c CVE-2019-16163 — oniguruma: Stack exhaustion in regcomp.c because of recursion in regparse.c CVE-2019-19203 — oniguruma: Heap-based buffer over-read in function gb18030_mbc_enc_len in file gb18030.c CVE-2019-19204 — oniguruma: Heap-based buffer over-read in function fetch_interval_quantifier in regparse.c CVE-2019-19246 — oniguruma: Heap-based buffer overflow in str_lower_case_match in regexec.c CVE-2019-20454 — pcre: Out of bounds read in JIT mode when \X is used in non-UTF mode CVE-2020-7059 — php: Out of bounds read in php_strip_tags_ex CVE-2020-7060 — php: Global buffer-overflow in mbfl_filt_conv_big5_wchar function CVE-2020-7062 — php: NULL pointer dereference in PHP session upload progress CVE-2020-7063 — php: Files added to tar with Phar::buildFromIterator have all-access permissions CVE-2020-7064 — php: Information disclosure in exif_read_data() function CVE-2020-7065 — php: Using mb_strtolower() function with UTF-32LE encoding leads to potential code execution CVE-2020-7066 — php: Information disclosure in function get_headers

🎯 Affected products200

  • Red Hat Enterprise Linux AppStream (v. 8)
  • apcu-panel-0:5.1.17-1.module+el8.1.0+3189+a1bff096.noarch (php:7.3) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • libzip-0:1.5.2-1.module+el8.1.0+3189+a1bff096.aarch64 (php:7.3) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • libzip-0:1.5.2-1.module+el8.1.0+3189+a1bff096.ppc64le (php:7.3) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • libzip-0:1.5.2-1.module+el8.1.0+3189+a1bff096.s390x (php:7.3) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • libzip-0:1.5.2-1.module+el8.1.0+3189+a1bff096.src (php:7.3) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • libzip-0:1.5.2-1.module+el8.1.0+3189+a1bff096.x86_64 (php:7.3) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • libzip-debuginfo-0:1.5.2-1.module+el8.1.0+3189+a1bff096.aarch64 (php:7.3) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • libzip-debuginfo-0:1.5.2-1.module+el8.1.0+3189+a1bff096.ppc64le (php:7.3) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • libzip-debuginfo-0:1.5.2-1.module+el8.1.0+3189+a1bff096.s390x (php:7.3) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • libzip-debuginfo-0:1.5.2-1.module+el8.1.0+3189+a1bff096.x86_64 (php:7.3) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • libzip-debugsource-0:1.5.2-1.module+el8.1.0+3189+a1bff096.aarch64 (php:7.3) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • libzip-debugsource-0:1.5.2-1.module+el8.1.0+3189+a1bff096.ppc64le (php:7.3) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • libzip-debugsource-0:1.5.2-1.module+el8.1.0+3189+a1bff096.s390x (php:7.3) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • libzip-debugsource-0:1.5.2-1.module+el8.1.0+3189+a1bff096.x86_64 (php:7.3) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • libzip-devel-0:1.5.2-1.module+el8.1.0+3189+a1bff096.aarch64 (php:7.3) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • libzip-devel-0:1.5.2-1.module+el8.1.0+3189+a1bff096.ppc64le (php:7.3) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • libzip-devel-0:1.5.2-1.module+el8.1.0+3189+a1bff096.s390x (php:7.3) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • libzip-devel-0:1.5.2-1.module+el8.1.0+3189+a1bff096.x86_64 (php:7.3) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • libzip-tools-0:1.5.2-1.module+el8.1.0+3189+a1bff096.aarch64 (php:7.3) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • libzip-tools-0:1.5.2-1.module+el8.1.0+3189+a1bff096.ppc64le (php:7.3) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • libzip-tools-0:1.5.2-1.module+el8.1.0+3189+a1bff096.s390x (php:7.3) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • libzip-tools-0:1.5.2-1.module+el8.1.0+3189+a1bff096.x86_64 (php:7.3) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • libzip-tools-debuginfo-0:1.5.2-1.module+el8.1.0+3189+a1bff096.aarch64 (php:7.3) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • libzip-tools-debuginfo-0:1.5.2-1.module+el8.1.0+3189+a1bff096.ppc64le (php:7.3) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • libzip-tools-debuginfo-0:1.5.2-1.module+el8.1.0+3189+a1bff096.s390x (php:7.3) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • libzip-tools-debuginfo-0:1.5.2-1.module+el8.1.0+3189+a1bff096.x86_64 (php:7.3) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • php-0:7.3.20-1.module+el8.2.0+7373+b272fdef.aarch64 (php:7.3) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • php-0:7.3.20-1.module+el8.2.0+7373+b272fdef.ppc64le (php:7.3) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • php-0:7.3.20-1.module+el8.2.0+7373+b272fdef.s390x (php:7.3) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • +170 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing the updated packages, the httpd daemon must be restarted for the update to take effect. Workaround: Ensure that `post_max_size` is set to a value less than 2GB, or remains default.

🔗 References (25)