ZeroHour

CVE-2019-11044

PoC
CVSS 3.1
7.5 high
EPSS
5%p92
Published
()
Modified
Description

In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 on Windows, PHP link() function accepts filenames with embedded \0 byte and treats them as terminating at that byte. This could lead to security vulnerabilities, e.g. in applications checking paths that the code is allowed to access.

Vendors
phptenablefedoraproject
Products
php, security center, fedora
Weakness
CWE-170
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.