Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-31626

Опубликовано: 16 июн. 2022
Источник: debian
EPSS Средний

Описание

In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when pdo_mysql extension with mysqlnd driver, if the third party is allowed to supply host to connect to and the password for the connection, password of excessive length can trigger a buffer overflow in PHP, which can lead to a remote code execution vulnerability.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
php8.1fixed8.1.7-1package
php7.4removedpackage
php7.3removedpackage
php7.0removedpackage
php7.0postponedstretchpackage

Примечания

  • Fixed in 7.4.30, 8.0.20, 8.1.7

  • PHP Bug: https://bugs.php.net/bug.php?id=81719

  • https://github.com/php/php-src/commit/58006537fc5f133ae8549efe5118cde418b3ace9 (php-7.4.30)

EPSS

Процентиль: 94%
0.14525
Средний

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 3 лет назад

In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when pdo_mysql extension with mysqlnd driver, if the third party is allowed to supply host to connect to and the password for the connection, password of excessive length can trigger a buffer overflow in PHP, which can lead to a remote code execution vulnerability.

CVSS3: 8.8
redhat
около 3 лет назад

In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when pdo_mysql extension with mysqlnd driver, if the third party is allowed to supply host to connect to and the password for the connection, password of excessive length can trigger a buffer overflow in PHP, which can lead to a remote code execution vulnerability.

CVSS3: 7.5
nvd
около 3 лет назад

In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when pdo_mysql extension with mysqlnd driver, if the third party is allowed to supply host to connect to and the password for the connection, password of excessive length can trigger a buffer overflow in PHP, which can lead to a remote code execution vulnerability.

rocky
почти 3 года назад

Important: php:8.0 security update

rocky
почти 3 года назад

Important: php:7.4 security update

EPSS

Процентиль: 94%
0.14525
Средний