Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-31628

Опубликовано: 28 сент. 2022
Источник: debian
EPSS Низкий

Описание

In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the phar uncompressor code would recursively uncompress "quines" gzip files, resulting in an infinite loop.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
php8.1fixed8.1.12-1package
php7.4removedpackage
php7.3removedpackage

Примечания

  • Fixed in 8.1.11, 7.4.32

  • PHP Bug: https://bugs.php.net/bug.php?id=81726

  • https://github.com/php/php-src/commit/404e8bdb68350931176a5bdc86fc417b34fb583d

  • https://github.com/php/php-src/commit/432bf196d59bcb661fcf9cb7029cea9b43f490af

EPSS

Процентиль: 8%
0.00031
Низкий

Связанные уязвимости

CVSS3: 2.3
ubuntu
около 3 лет назад

In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the phar uncompressor code would recursively uncompress "quines" gzip files, resulting in an infinite loop.

CVSS3: 4.4
redhat
около 3 лет назад

In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the phar uncompressor code would recursively uncompress "quines" gzip files, resulting in an infinite loop.

CVSS3: 2.3
nvd
около 3 лет назад

In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the phar uncompressor code would recursively uncompress "quines" gzip files, resulting in an infinite loop.

CVSS3: 2.3
msrc
около 1 месяца назад

phar wrapper can occur dos when using quine gzip file

CVSS3: 5.5
github
около 3 лет назад

In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the phar uncompressor code would recursively uncompress "quines" gzip files, resulting in an infinite loop.

EPSS

Процентиль: 8%
0.00031
Низкий