CVE-2020-7068

Use of freed hash key in the phar_parse_zipfile function

In PHP versions 7.2.x below 7.2.33, 7.3.x below 7.3.21 and 7.4.x below 7.4.9, while processing PHAR files using phar extension, phar_parse_zipfile could be tricked into accessing freed memory, which could lead to a crash or information disclosure.


We have discovered 347,540 live websites that are affected by CVE-2020-7068.

Run a Free Instant Scan




Affected Software

Product  PHP
Category Programming Languages
Vulnerable Domains347,540 live websites (4.73% of PHP install base)
Vulnerable Versions
  • from 7.2 through 7.2.33
  • from 7.3 through 7.3.21
  • from 7.4 through 7.4.9
Vulnerable Versions Count63 versions ( 12% of all versions)


Common Weakness Enumeration

CWE-416 Use After Free



Details

  • Published - Sep 9, 2020
  • Updated - Sep 17, 2024

Credits

  • grigoritchy at gmail dot com

Website Distribution by Country

Number of websites using CVE-2020-7068
United States117,220 websites



France126,296 websites
Germany10,937 websites
Russia10,439 websites
China10,021 websites
Japan6,322 websites
Poland5,741 websites
Netherlands5,712 websites
Italy4,880 websites
GB4,307 websites

Website Distribution by TLD

Number of websites using CVE-2020-7068
.com124,367 websites
.ru67,741 websites
.fr51,727 websites
.org11,510 websites
.net9,855 websites
.be6,401 websites
.de5,766 websites
.pl5,468 websites
.it4,779 websites
.nl3,178 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2020-7068

Top websites that are affected by CVE-2020-7068. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*.cn China*,***
*****.pl Poland*,***
****.neustar United States*,***
*********.com China*,***
****.com China*,***
*****.com United States*,***
******.com France*,***
**********.com France*,***
***.****.gov United States*,***
*****.**.com China*,***
See full domain list

FAQ

CVE-2020-7068 is Use After Free in PHP
A total of 347,540 websites have been identified as vulnerable to CVE-2020-7068, based on global website indexing conducted by WebTechSurvey.
The PHP is affected by the CVE-2020-7068 vulnerability.
PHP versions up to 7.4.9 are vulnerable to CVE-2020-7068.
CVE-2020-7068 is resolved in version 7.4.9 of PHP.