CVE-2020-7068


Use of freed hash key in the phar_parse_zipfile function

In PHP versions 7.2.x below 7.2.33, 7.3.x below 7.3.21 and 7.4.x below 7.4.9, while processing PHAR files using phar extension, phar_parse_zipfile could be tricked into accessing freed memory, which could lead to a crash or information disclosure.



We have discovered 684,803 live websites that are affected by CVE-2020-7068.

Contact us to get more info




Affected Software

Product  PHP
Category Programming Languages
Vulnerable Versions
  • from 7.2 before 7.2.33
  • from 7.3 before 7.3.21
  • from 7.4 before 7.4.9
Total Vulnerable Versions507
Vulnerable Domains684,803 live websites (5.66% of PHP install base)


Common Weakness Enumeration


CWE-416 Use After Free


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2020-7068 and the relative popularity of websites


Details

  • Published - Aug 3, 2020
  • Updated - Jul 23, 2021

Credits

  • grigoritchy at gmail dot com





Countries

United States134,960 websites



France252,388 websites
Russia71,672 websites
China22,748 websites
Germany18,424 websites
Italy14,234 websites
Poland14,083 websites
Belgium12,267 websites
Spain12,010 websites
Japan11,784 websites

TLDs

.com276,748 websites
.fr112,113 websites
.ru67,842 websites
.org27,913 websites
.net19,519 websites
.be13,637 websites
.de11,655 websites
.pl11,009 websites
.it10,606 websites
.nl7,788 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2020-7068 through included software libraries and plugins.



References


Websites affected by CVE-2020-7068

Top websites that are affected by CVE-2020-7068. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***.*****.cz Czech Republic*,***
*.cn China*,***
***.*.cn China*,***
***.*****.pl Poland*,***
*******.com Germany*,***
*****.***.cn China*,***
***.*****.***.cn China*,***
*****.cn China*,***
***.*****.cn China*,***
***.*********.com China*,***
See full domain list