CVE-2020-7069

Source
https://cve.org/CVERecord?id=CVE-2020-7069
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-7069.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2020-7069
Aliases
Downstream
Related
Published
2020-10-02T15:15:12.670Z
Modified
2026-02-06T05:19:56.132562Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when AES-CCM mode is used with openssl_encrypt() function with 12 bytes IV, only first 7 bytes of the IV is actually used. This can lead to both decreased security and incorrect encryption data.

References

Affected packages

Git / github.com/perl/perl5

Affected ranges

Type
GIT
Repo
https://github.com/perl/perl5
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

Other
GitLive-blead
perl-5a2
perl-5a9
if-0.*
if-0.0602
perl-1.*
perl-1.0
perl-2.*
perl-2.0
perl-3.*
perl-3.000
perl-3.044
perl-4.*
perl-4.0.00
perl-4.0.36
perl-5.*
perl-5.000
perl-5.000o
perl-5.001
perl-5.001n
perl-5.002
perl-5.002_01
perl-5.003
perl-5.003_01
perl-5.003_02
perl-5.003_03
perl-5.003_04
perl-5.003_05
perl-5.003_07
perl-5.003_08
perl-5.003_09
perl-5.003_10
perl-5.003_11
perl-5.003_12
perl-5.003_13
perl-5.003_14
perl-5.003_15
perl-5.003_16
perl-5.003_17
perl-5.003_18
perl-5.003_19
perl-5.003_20
perl-5.003_21
perl-5.003_22
perl-5.003_23
perl-5.003_24
perl-5.003_25
perl-5.003_26
perl-5.003_27
perl-5.003_28
perl-5.003_90
perl-5.003_91
perl-5.003_92
perl-5.003_93
perl-5.003_94
perl-5.003_95
perl-5.003_96
perl-5.003_97
perl-5.003_97a
perl-5.003_97b
perl-5.003_97c
perl-5.003_97d
perl-5.003_97e
perl-5.003_97f
perl-5.003_97g
perl-5.003_97h
perl-5.003_97i
perl-5.003_97j
perl-5.003_98
perl-5.003_99
perl-5.003_99a
perl-5.004
perl-5.004_01
perl-5.004_02
perl-5.004_03
perl-5.004_04
perl-5.005
perl-5.005_01
perl-5.005_02
perl-5.6.0
perl-5.7.0
perl-5.7.1
perl-5.7.2
perl-5.7.3
perl-5.8.0
perl-5.9.0
perl-5.9.1
perl-5.9.2
perl-5.9.3
perl-5.9.4
perl-5.9.5
v5.*
v5.10.0
v5.11.0
v5.11.1
v5.11.2
v5.11.3
v5.11.4
v5.11.5
v5.12.0
v5.12.0-RC0
v5.12.0-RC1
v5.12.0-RC2
v5.12.0-RC3
v5.12.0-RC4
v5.12.0-RC5
v5.13.0
v5.13.1
v5.13.10
v5.13.11
v5.13.2
v5.13.3
v5.13.4
v5.13.5
v5.13.6
v5.13.7
v5.13.8
v5.13.9
v5.14.0
v5.14.0-RC1
v5.14.0-RC2
v5.14.0-RC3
v5.15.0
v5.15.1
v5.15.2
v5.15.3
v5.15.4
v5.15.5
v5.15.6
v5.15.7
v5.15.8
v5.15.9
v5.16.0
v5.16.0-RC1
v5.16.0-RC2
v5.17.0
v5.17.1
v5.17.10
v5.17.11
v5.17.2
v5.17.3
v5.17.4
v5.17.5
v5.17.6
v5.17.7
v5.17.7.0
v5.17.8
v5.17.9
v5.18.0
v5.18.0-RC1
v5.18.0-RC2
v5.18.0-RC3
v5.18.0-RC4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-7069.json"

Git / github.com/php/php-src

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-7069.json"