{"id":"BIT-php-2020-7069","summary":"Wrong ciphertext/tag in AES-CCM encryption for a 12 bytes IV","details":"In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when AES-CCM mode is used with openssl_encrypt() function with 12 bytes IV, only first 7 bytes of the IV is actually used. This can lead to both decreased security and incorrect encryption data.","aliases":["BIT-libphp-2020-7069","BIT-php-min-2020-7069","CVE-2020-7069"],"modified":"2025-08-11T15:13:48.854894Z","published":"2024-03-06T11:06:06.701Z","database_specific":{"cpes":["cpe:2.3:a:php:php:*:*:*:*:*:*:*:*"],"severity":"Medium"},"references":[{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00045.html"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00067.html"},{"type":"WEB","url":"https://bugs.php.net/bug.php?id=79601"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7EVDN7D3IB4EAI4D3ZOM2OJKQ5SD7K4E/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/P2J3ZZDHCSX65T5QWV4AHBN7MOJXBEKG/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RRU57N3OSYZPOMFWPRDNVH7EMYOTSZ66/"},{"type":"WEB","url":"https://security.gentoo.org/glsa/202012-16"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20201016-0001/"},{"type":"WEB","url":"https://usn.ubuntu.com/4583-1/"},{"type":"WEB","url":"https://www.debian.org/security/2021/dsa-4856"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpuApr2021.html"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpuoct2021.html"},{"type":"WEB","url":"https://www.tenable.com/security/tns-2021-14"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-7069"}],"affected":[{"package":{"name":"php","ecosystem":"Bitnami","purl":"pkg:bitnami/php"},"ranges":[{"type":"SEMVER","events":[{"introduced":"7.2.0"},{"fixed":"7.2.34"},{"introduced":"7.3.0"},{"fixed":"7.3.23"},{"introduced":"7.4.0"},{"fixed":"7.4.11"}]}],"database_specific":{"source":"https://github.com/bitnami/vulndb/tree/main/data/php/BIT-php-2020-7069.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"}]}],"schema_version":"1.7.3"}