UNKNOWNCVE-2020-7062
Null Pointer Dereference in PHP Session Upload Progress
Platform
php
Component
php
Fixed in
7.4.3
In PHP versions 7.2.x below 7.2.28, 7.3.x below 7.3.15 and 7.4.x below 7.4.3, when using file upload functionality, if upload progress tracking is enabled, but session.upload_progress.cleanup is set to 0 (disabled), and the file upload fails, the upload procedure would try to clean up data that does not exist and encounter null pointer dereference, which would likely lead to a crash.
How to fix
Actualice a la última versión de PHP. Específicamente, actualice a la versión 7.2.28 o superior, 7.3.15 o superior, o 7.4.3 o superior. Esto corrige la vulnerabilidad de desreferencia de puntero nulo.
Monitor your dependencies automatically
Get notified when new vulnerabilities affect your projects. Free forever.
Start free