VDB
CVE-2018-20783
CVE-2018-20783
PUBLISHED
In PHP before 5.6.39, 7.x before 7.0.33, 7.1.x before 7.1.25, and 7.2.x before 7.2.13, a buffer over-read in PHAR reading functions may allow an attacker to read allocated or unallocated memory past the actual data when trying to parse a .phar file. This is related to phar_parse_pharfile in ext/phar/phar.c.
EPSS 5.10% · 90.0th percentile
Risk Scores
EPSS Score
5.10%
90.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:Pro:14.04:LTS | php5 | 0, 5.5.3+dfsg-1ubuntu2, 5.5.6+dfsg-1ubuntu1 |
| Ubuntu:16.04:LTS | php7.0 | 7.0.15-0ubuntu0.16.04.1, 7.0.18-0ubuntu0.16.04.1, 7.0.22-0ubuntu0.16.04.1 |
| Ubuntu:18.04:LTS | php7.2 | 7.2.2-1ubuntu1, 7.2.2-1ubuntu2, 7.2.3-1ubuntu1 |
Exploit Intelligence
Timeline
- CVE Published
- Oct 10, 2020 PoC Published
- Apr 14, 2021 EPSS Score
- Feb 4, 2022 EPSS Score
- Mar 17, 2025 EPSS Score
- Mar 29, 2025 EPSS Score
- May 1, 2025 EPSS Score
- May 4, 2025 EPSS Score
- May 28, 2025 EPSS Score
- Jun 1, 2025 EPSS Score
- Jun 4, 2025 EPSS Score
- Jun 10, 2025 EPSS Score
References
- https://ubuntu.com/security/CVE-2018-20783 third-party-advisory
- http://php.net/ChangeLog-5.php third-party-advisory
- http://php.net/ChangeLog-7.php third-party-advisory
- https://ubuntu.com/security/notices/USN-3566-2 vendor-advisory
- https://www.cve.org/CVERecord?id=CVE-2018-20783 third-party-advisory