Null Pointer Dereference in PHP Session Upload Progress
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.5epss 3.6%
exploitation probability
3.6%top 12% of all CVEs
observed exploitation
nono source reports it
In PHP versions 7.2.x below 7.2.28, 7.3.x below 7.3.15 and 7.4.x below 7.4.3, when using file upload functionality, if upload progress tracking is enabled, but session.upload_progress.cleanup is set to 0 (disabled), and the file upload fails, the upload procedure would try to clean up data that does not exist and encounter null pointer dereference, which would likely lead to a crash.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
PHP Group · PHPReferences
http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00023.htmlhttps://bugs.php.net/bug.php?id=79221https://lists.debian.org/debian-lts-announce/2020/03/msg00034.htmlhttps://security.gentoo.org/glsa/202003-57https://usn.ubuntu.com/4330-1/https://www.debian.org/security/2020/dsa-4717https://www.debian.org/security/2020/dsa-4719https://www.tenable.com/security/tns-2021-14