CVE-2022-31627

In PHP versions 8.1.x below 8.1.8, when fileinfo functions, such as finfo_buffer, due to incorrect patch applied to the third party code from libmagic, incorrect function may be used to free allocated memory, which may lead to heap corruption.
References
Link Resource
https://bugs.php.net/bug.php?id=81723 Exploit Issue Tracking Patch Third Party Advisory
https://security.gentoo.org/glsa/202209-20 Third Party Advisory
https://security.netapp.com/advisory/ntap-20220826-0008/ Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:php:php:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2022-07-28 06:15

Updated : 2024-02-28 19:29


NVD link : CVE-2022-31627

Mitre link : CVE-2022-31627

CVE.ORG link : CVE-2022-31627


JSON object : View

Products Affected

php

  • php
CWE
CWE-787

Out-of-bounds Write

CWE-590

Free of Memory not on the Heap