In PHP versions 7.2.x below 7.2.30, 7.3.x below 7.3.17 and 7.4.x below 7.4.5, if PHP is compiled with EBCDIC support (uncommon), urldecode() function can be made to access locations past the allocated memory, due to erroneously using signed numbers as array indexes.
{
"unresolved_ranges": [
{
"source": "CPE_FIELD",
"extracted_events": [
{
"introduced": "8.0.0.0"
},
{
"last_affected": "8.4.0.5"
}
],
"cpe": "cpe:2.3:a:oracle:communications_diameter_signaling_router:*:*:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"fixed": "5.19.0"
}
],
"cpe": "cpe:2.3:a:tenable:tenable.sc:*:*:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "10.0"
}
],
"cpe": "cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "9.0"
}
],
"cpe": "cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"
}
]
}{
"source": "CPE_FIELD",
"extracted_events": [
{
"introduced": "7.2.0"
},
{
"fixed": "7.2.30"
},
{
"introduced": "7.3.0"
},
{
"fixed": "7.3.17"
},
{
"introduced": "7.4.0"
},
{
"fixed": "7.4.5"
}
],
"cpe": "cpe:2.3:a:php:php:*:*:*:*:*:*:*:*"
}"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-7067.json"
[
{
"target": {
"function": "php_raw_url_decode",
"file": "ext/standard/url.c"
},
"signature_version": "v1",
"source": "https://github.com/php/php-src/commit/2c0d56cc150ada2355319c418c0c6e8321ef7b0f",
"signature_type": "Function",
"deprecated": false,
"id": "CVE-2020-7067-1cafb47a",
"digest": {
"function_hash": "40565887675130562443727052077638606803",
"length": 475.0
}
},
{
"deprecated": false,
"signature_version": "v1",
"source": "https://github.com/php/php-src/commit/2c0d56cc150ada2355319c418c0c6e8321ef7b0f",
"signature_type": "Line",
"target": {
"file": "ext/standard/url.c"
},
"id": "CVE-2020-7067-96d24e0b",
"digest": {
"threshold": 0.9,
"line_hashes": [
"229641027241768780455332400035790589213",
"325167784308788717541731998735878028213",
"192017146838867819246149091574669861050",
"149578118580867487196755427987601782041",
"229641027241768780455332400035790589213",
"325167784308788717541731998735878028213",
"192017146838867819246149091574669861050",
"149578118580867487196755427987601782041"
]
}
},
{
"deprecated": false,
"signature_version": "v1",
"source": "https://github.com/php/php-src/commit/2c0d56cc150ada2355319c418c0c6e8321ef7b0f",
"signature_type": "Function",
"target": {
"function": "php_url_decode",
"file": "ext/standard/url.c"
},
"id": "CVE-2020-7067-b285b1b5",
"digest": {
"function_hash": "181543715275648914325665755639281675361",
"length": 518.0
}
}
]
"2026-04-11T23:12:10Z"