Buffer underflow in bc_shift_addsub
8Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 3.7epss 4.1%
exploitation probability
4.1%top 10% of all CVEs
observed exploitation
nono source reports it
In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP bcmath extension functions on some systems, including Windows, can be tricked into reading beyond the allocated space by supplying it with string containing characters that are identified as numeric by the OS but aren't ASCII numbers. This can read to disclosure of the content of some memory locations.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected products
PHP Group · PHPReferences
http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00036.htmlhttps://bugs.php.net/bug.php?id=78878https://lists.debian.org/debian-lts-announce/2019/12/msg00034.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N7GCOAE6KVHYJ3UQ4KLPLTGSLX6IRVRN/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XWRQPYXVG43Q7DXMXH6UVWMKWGUW552F/https://seclists.org/bugtraq/2020/Feb/27https://seclists.org/bugtraq/2020/Feb/31https://seclists.org/bugtraq/2021/Jan/3https://security.netapp.com/advisory/ntap-20200103-0002/https://support.f5.com/csp/article/K48866433?utm_source=f5support&%3Butm_medium=RSShttps://usn.ubuntu.com/4239-1/https://www.debian.org/security/2020/dsa-4626