CVE-2020-7061

heap-buffer-overflow in phar_extract_file

In PHP versions 7.3.x below 7.3.15 and 7.4.x below 7.4.3, while extracting PHAR files on Windows using phar extension, certain content inside PHAR file could lead to one-byte read past the allocated buffer. This could potentially lead to information disclosure or crash.


We have discovered 141,544 live websites that are affected by CVE-2020-7061.

Run a Free Instant Scan




Affected Software

Product  PHP
Category Programming Languages
Vulnerable Domains141,544 live websites (1.94% of PHP install base)
Vulnerable Versions
  • from 7.3 through 7.3.15
  • from 7.4 through 7.4.3
Vulnerable Versions Count18 versions ( 3.49% of all versions)


Common Weakness Enumeration

CWE-125 Out-of-bounds Read



Details

  • Published - Feb 27, 2020
  • Updated - Sep 17, 2024

Website Distribution by Country

Number of websites using CVE-2020-7061
United States11,615 websites



France96,277 websites
China4,268 websites
Russia4,089 websites
Poland3,691 websites
Germany2,560 websites
Italy2,265 websites
Spain2,229 websites
Japan1,683 websites
Belgium1,628 websites

Website Distribution by TLD

Number of websites using CVE-2020-7061
.com54,876 websites
.fr40,282 websites
.org5,224 websites
.be4,766 websites
.net3,903 websites
.pl3,637 websites
.ru3,621 websites
.it2,678 websites
.eu1,948 websites
.es1,639 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2020-7061

Top websites that are affected by CVE-2020-7061. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******.com France*,***
******.com France*,***
*********.be France**,***
*********.fr France**,***
****.*********.com China**,***
***********.******.**.com United States**,***
****.***********.com United States**,***
**********.*********.com United States**,***
**********.com United States**,***
****.com France**,***
See full domain list

FAQ

CVE-2020-7061 is Out-of-bounds Read in PHP
A total of 141,544 websites have been identified as vulnerable to CVE-2020-7061, based on global website indexing conducted by WebTechSurvey.
The PHP is affected by the CVE-2020-7061 vulnerability.
PHP versions up to 7.4.3 are vulnerable to CVE-2020-7061.
CVE-2020-7061 is resolved in version 7.4.3 of PHP.