CVE-2020-7065


mb_strtolower (UTF-32LE): stack-buffer-overflow at php_unicode_tolower_full

In PHP versions 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using mb_strtolower() function with UTF-32LE encoding, certain invalid strings could cause PHP to overwrite stack-allocated buffer. This could lead to memory corruption, crashes and potentially code execution.



We have discovered 413,355 live websites that are affected by CVE-2020-7065.

Contact us to get more info




Affected Software

Product  PHP
Category Programming Languages
Vulnerable Versions
  • from 7.3 before 7.3.16
  • from 7.4 before 7.4.4
Total Vulnerable Versions507
Vulnerable Domains413,355 live websites (3.42% of PHP install base)


Common Weakness Enumeration


CWE-121 Stack-based Buffer Overflow


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2020-7065 and the relative popularity of websites


Details

  • Published - Mar 17, 2020
  • Updated - Oct 20, 2021

Credits

  • anatoly dot trosinenko at gmail dot com





Countries

United States95,940 websites



France204,444 websites
Russia9,599 websites
Belgium9,415 websites
Poland8,932 websites
Italy8,085 websites
Germany7,793 websites
China7,685 websites
Spain6,745 websites
Canada5,362 websites

TLDs

.com190,079 websites
.fr91,337 websites
.org19,859 websites
.net12,409 websites
.be10,584 websites
.ru8,427 websites
.pl7,068 websites
.it6,245 websites
.de4,768 websites
.eu4,403 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2020-7065 through included software libraries and plugins.



References


Websites affected by CVE-2020-7065

Top websites that are affected by CVE-2020-7065. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***.*****.pl Poland*,***
*******.com Germany*,***
******.com France*,***
**********.com France*,***
***.*********.com United States*,***
************.org France*,***
******.com United States*,***
***.******.com France*,***
***.****.com Spain*,***
***.*********.com United States*,***
See full domain list