Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-31628

Опубликовано: 28 сент. 2022
Источник: debian
EPSS Низкий

Описание

In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the phar uncompressor code would recursively uncompress "quines" gzip files, resulting in an infinite loop.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
php8.1fixed8.1.12-1package
php7.4removedpackage
php7.3removedpackage

Примечания

  • Fixed in 8.1.11, 7.4.32

  • PHP Bug: https://bugs.php.net/bug.php?id=81726

  • https://github.com/php/php-src/commit/404e8bdb68350931176a5bdc86fc417b34fb583d

  • https://github.com/php/php-src/commit/432bf196d59bcb661fcf9cb7029cea9b43f490af

EPSS

Процентиль: 13%
0.00044
Низкий

Связанные уязвимости

CVSS3: 2.3
ubuntu
больше 3 лет назад

In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the phar uncompressor code would recursively uncompress "quines" gzip files, resulting in an infinite loop.

CVSS3: 4.4
redhat
больше 3 лет назад

In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the phar uncompressor code would recursively uncompress "quines" gzip files, resulting in an infinite loop.

CVSS3: 2.3
nvd
больше 3 лет назад

In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the phar uncompressor code would recursively uncompress "quines" gzip files, resulting in an infinite loop.

CVSS3: 2.3
msrc
6 месяцев назад

phar wrapper can occur dos when using quine gzip file

CVSS3: 5.5
github
больше 3 лет назад

In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the phar uncompressor code would recursively uncompress "quines" gzip files, resulting in an infinite loop.

EPSS

Процентиль: 13%
0.00044
Низкий