CVE-2019-9020 PUBLISHED

An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. Invalid input to the function xmlrpc_decode() can lead to an invalid memory access (heap out of bounds read or read after free). This is related to xml_elem_parse_buf in ext/xmlrpc/libxmlrpc/xml_element.c.

EPSS 2.39% · 84.9th percentile

Risk Scores

EPSS Score
2.39%
84.9th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSphp7.27.2.10-0ubuntu0.18.04.1, 7.2.7-0ubuntu0.18.04.2, 7.2.7-0ubuntu0.18.04.1
Ubuntu:14.04:LTSphp55.5.9+dfsg-1ubuntu4, 5.5.9+dfsg-1ubuntu4.1, 5.5.9+dfsg-1ubuntu4.2
Ubuntu:16.04:LTSphp7.07.0.3-9ubuntu1, 7.0.4-5ubuntu1, 7.0.4-5ubuntu2

Timeline

References

Open in Interactive Console →