CVE-2020-7069

Name
CVE-2020-7069
Description
In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when AES-CCM mode is used with openssl_encrypt() function with 12 bytes IV, only first 7 bytes of the IV is actually used. This can lead to both decreased security and incorrect encryption data.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Issue Tracking https://bugs.php.net/bug.php?id=79601
Mailing List https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RRU57N3OSYZPOMFWPRDNVH7EMYOTSZ66/
Third Party Advisory https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7EVDN7D3IB4EAI4D3ZOM2OJKQ5SD7K4E/
Third Party Advisory https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/P2J3ZZDHCSX65T5QWV4AHBN7MOJXBEKG/
Third Party Advisory https://security.netapp.com/advisory/ntap-20201016-0001/
Mailing List http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00045.html
Third Party Advisory https://usn.ubuntu.com/4583-1/
Mailing List http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00067.html
Third Party Advisory https://security.gentoo.org/glsa/202012-16
Third Party Advisory https://www.debian.org/security/2021/dsa-4856
MISC https://www.oracle.com/security-alerts/cpuApr2021.html
CONFIRM https://www.tenable.com/security/tns-2021-14
MISC https://www.oracle.com/security-alerts/cpuoct2021.html

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:php:php:*:*:*:*:*:*:*:* php >= 7.2.0 < 7.2.34
cpe:2.3:a:php:php:*:*:*:*:*:*:*:* php >= 7.3.0 < 7.3.23
cpe:2.3:a:php:php:*:*:*:*:*:*:*:* php >= 7.4.0 < 7.4.11

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
php7 edge-community 7.4.11-r0 None fixed