Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-31627

Опубликовано: 28 июл. 2022
Источник: debian
EPSS Низкий

Описание

In PHP versions 8.1.x below 8.1.8, when fileinfo functions, such as finfo_buffer, due to incorrect patch applied to the third party code from libmagic, incorrect function may be used to free allocated memory, which may lead to heap corruption.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
php8.1fixed8.1.12-1package
php7.4not-affectedpackage
php7.3not-affectedpackage

Примечания

  • Fixed in 8.1.8

  • PHP Bug: https://bugs.php.net/bug.php?id=81723

  • https://github.com/php/php-src/commit/ca6d511fa54b34d5b75bf120a86482a1b9e1e686

EPSS

Процентиль: 34%
0.0013
Низкий

Связанные уязвимости

CVSS3: 7.7
ubuntu
почти 3 года назад

In PHP versions 8.1.x below 8.1.8, when fileinfo functions, such as finfo_buffer, due to incorrect patch applied to the third party code from libmagic, incorrect function may be used to free allocated memory, which may lead to heap corruption.

CVSS3: 7.5
redhat
почти 3 года назад

In PHP versions 8.1.x below 8.1.8, when fileinfo functions, such as finfo_buffer, due to incorrect patch applied to the third party code from libmagic, incorrect function may be used to free allocated memory, which may lead to heap corruption.

CVSS3: 7.7
nvd
почти 3 года назад

In PHP versions 8.1.x below 8.1.8, when fileinfo functions, such as finfo_buffer, due to incorrect patch applied to the third party code from libmagic, incorrect function may be used to free allocated memory, which may lead to heap corruption.

CVSS3: 9.8
msrc
9 месяцев назад

Описание отсутствует

CVSS3: 9.8
github
почти 3 года назад

In PHP versions 8.1.x below 8.1.8, when fileinfo functions, such as finfo_buffer, due to incorrect patch applied to the third party code from libmagic, incorrect function may be used to free allocated memory, which may lead to heap corruption.

EPSS

Процентиль: 34%
0.0013
Низкий