CVE-2020-7064


Use-of-uninitialized-value in exif

In PHP versions 7.2.x below 7.2.9, 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while parsing EXIF data with exif_read_data() function, it is possible for malicious data to cause PHP to read one byte of uninitialized memory. This could potentially lead to information disclosure or crash.



We have discovered 615,085 live websites that are affected by CVE-2020-7064.

Contact us to get more info




Affected Software

Product  PHP
Category Programming Languages
Vulnerable Versions
  • from 7.2 before 7.2.29
  • from 7.3 before 7.3.16
  • from 7.4 before 7.4.4
Total Vulnerable Versions507
Vulnerable Domains615,085 live websites (5.08% of PHP install base)


Common Weakness Enumeration


CWE-125 Out-of-bounds Read


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2020-7064 and the relative popularity of websites


Details

  • Published - Feb 17, 2020
  • Updated - Jul 23, 2021

Credits

  • From https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=19581





Countries

United States121,921 websites



France244,506 websites
Russia66,646 websites
China20,496 websites
Germany14,128 websites
Poland12,766 websites
Italy11,879 websites
Belgium11,568 websites
Spain9,668 websites
Netherlands9,609 websites

TLDs

.com251,338 websites
.fr109,052 websites
.ru64,342 websites
.org25,211 websites
.net16,852 websites
.be12,963 websites
.pl10,003 websites
.it8,947 websites
.de8,747 websites
.nl6,806 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2020-7064 through included software libraries and plugins.



References


Websites affected by CVE-2020-7064

Top websites that are affected by CVE-2020-7064. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***.*****.cz Czech Republic*,***
*.cn China*,***
***.*.cn China*,***
***.*****.pl Poland*,***
*******.com Germany*,***
*****.***.cn China*,***
***.*****.***.cn China*,***
*****.cn China*,***
***.*****.cn China*,***
***.*********.com China*,***
See full domain list