CVE-2022-31627

In PHP versions 8.1.x below 8.1.8, when fileinfo functions, such as finfo_buffer, due to incorrect patch applied to the third party code from libmagic, incorrect function may be used to free allocated memory, which may lead to heap corruption.
References
Link Resource
https://bugs.php.net/bug.php?id=81723 Exploit Issue Tracking Patch Third Party Advisory
https://security.gentoo.org/glsa/202209-20 Third Party Advisory
https://security.netapp.com/advisory/ntap-20220826-0008/ Third Party Advisory
https://bugs.php.net/bug.php?id=81723 Exploit Issue Tracking Patch Third Party Advisory
https://security.gentoo.org/glsa/202209-20 Third Party Advisory
https://security.netapp.com/advisory/ntap-20220826-0008/ Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:php:php:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:04

Type Values Removed Values Added
References () https://bugs.php.net/bug.php?id=81723 - Exploit, Issue Tracking, Patch, Third Party Advisory () https://bugs.php.net/bug.php?id=81723 - Exploit, Issue Tracking, Patch, Third Party Advisory
References () https://security.gentoo.org/glsa/202209-20 - Third Party Advisory () https://security.gentoo.org/glsa/202209-20 - Third Party Advisory
References () https://security.netapp.com/advisory/ntap-20220826-0008/ - Third Party Advisory () https://security.netapp.com/advisory/ntap-20220826-0008/ - Third Party Advisory
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : 7.7

Information

Published : 2022-07-28 06:15

Updated : 2024-11-21 07:04


NVD link : CVE-2022-31627

Mitre link : CVE-2022-31627

CVE.ORG link : CVE-2022-31627


JSON object : View

Products Affected

php

  • php
CWE
CWE-590

Free of Memory not on the Heap

CWE-787

Out-of-bounds Write