In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when AES-CCM mode is used with openssl_encrypt() function with 12 bytes IV, only first 7 bytes of the IV is actually used. This can lead to both decreased security and incorrect encryption data.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Canonical
Subscribe
|
Ubuntu Linux
Subscribe
|
|
Debian
Subscribe
|
Debian Linux
Subscribe
|
|
Fedoraproject
Subscribe
|
Fedora
Subscribe
|
|
Netapp
Subscribe
|
Clustered Data Ontap
Subscribe
|
|
Opensuse
Subscribe
|
Leap
Subscribe
|
|
Oracle
Subscribe
|
Communications Diameter Signaling Router
Subscribe
|
|
Php
Subscribe
|
Php
Subscribe
|
|
Redhat
Subscribe
|
|
|
Tenable
Subscribe
|
Tenable.sc
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-4856-1 | php7.3 security update |
EUVD |
EUVD-2020-28203 | In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when AES-CCM mode is used with openssl_encrypt() function with 12 bytes IV, only first 7 bytes of the IV is actually used. This can lead to both decreased security and incorrect encryption data. |
Ubuntu USN |
USN-4583-1 | PHP vulnerabilities |
Ubuntu USN |
USN-4583-2 | PHP vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: php
Published:
Updated: 2024-09-17T04:04:37.418Z
Reserved: 2020-01-15T00:00:00
Link: CVE-2020-7069
No data.
Status : Modified
Published: 2020-10-02T15:15:12.670
Modified: 2024-11-21T05:36:36.820
Link: CVE-2020-7069
OpenCVE Enrichment
No data.
Debian DSA
EUVD
Ubuntu USN