Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2c24-m9rj-gq8m

Опубликовано: 29 июл. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

In PHP versions 8.1.x below 8.1.8, when fileinfo functions, such as finfo_buffer, due to incorrect patch applied to the third party code from libmagic, incorrect function may be used to free allocated memory, which may lead to heap corruption.

In PHP versions 8.1.x below 8.1.8, when fileinfo functions, such as finfo_buffer, due to incorrect patch applied to the third party code from libmagic, incorrect function may be used to free allocated memory, which may lead to heap corruption.

EPSS

Процентиль: 34%
0.0013
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 7.7
ubuntu
почти 3 года назад

In PHP versions 8.1.x below 8.1.8, when fileinfo functions, such as finfo_buffer, due to incorrect patch applied to the third party code from libmagic, incorrect function may be used to free allocated memory, which may lead to heap corruption.

CVSS3: 7.5
redhat
почти 3 года назад

In PHP versions 8.1.x below 8.1.8, when fileinfo functions, such as finfo_buffer, due to incorrect patch applied to the third party code from libmagic, incorrect function may be used to free allocated memory, which may lead to heap corruption.

CVSS3: 7.7
nvd
почти 3 года назад

In PHP versions 8.1.x below 8.1.8, when fileinfo functions, such as finfo_buffer, due to incorrect patch applied to the third party code from libmagic, incorrect function may be used to free allocated memory, which may lead to heap corruption.

CVSS3: 9.8
msrc
9 месяцев назад

Описание отсутствует

CVSS3: 7.7
debian
почти 3 года назад

In PHP versions 8.1.x below 8.1.8, when fileinfo functions, such as fi ...

EPSS

Процентиль: 34%
0.0013
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-787