Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-31625

Опубликовано: 16 июн. 2022
Источник: debian
EPSS Низкий

Описание

In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when using Postgres database extension, supplying invalid parameters to the parametrized query may lead to PHP attempting to free memory using uninitialized data as pointers. This could lead to RCE vulnerability or denial of service.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
php8.1fixed8.1.7-1package
php7.4removedpackage
php7.3removedpackage
php7.0removedpackage
php7.0postponedstretchpackage

Примечания

  • Fixed in 7.4.30, 8.0.20, 8.1.7

  • PHP Bug: https://bugs.php.net/bug.php?id=81720

  • https://github.com/php/php-src/commit/55f6895f4b4c677272fd4ee1113acdbd99c4b5ab (php-7.4.30)

EPSS

Процентиль: 72%
0.00766
Низкий

Связанные уязвимости

CVSS3: 8.1
ubuntu
около 3 лет назад

In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when using Postgres database extension, supplying invalid parameters to the parametrized query may lead to PHP attempting to free memory using uninitialized data as pointers. This could lead to RCE vulnerability or denial of service.

CVSS3: 7
redhat
около 3 лет назад

In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when using Postgres database extension, supplying invalid parameters to the parametrized query may lead to PHP attempting to free memory using uninitialized data as pointers. This could lead to RCE vulnerability or denial of service.

CVSS3: 8.1
nvd
около 3 лет назад

In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when using Postgres database extension, supplying invalid parameters to the parametrized query may lead to PHP attempting to free memory using uninitialized data as pointers. This could lead to RCE vulnerability or denial of service.

rocky
почти 3 года назад

Moderate: php:7.4 security update

CVSS3: 9.8
github
около 3 лет назад

In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when using Postgres database extension, supplying invalid parameters to the parametrized query may lead to PHP attempting to free memory using uninitialized data as pointers. This could lead to RCE vulnerability or denial of service.

EPSS

Процентиль: 72%
0.00766
Низкий