Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-31627

Опубликовано: 08 июл. 2022
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

In PHP versions 8.1.x below 8.1.8, when fileinfo functions, such as finfo_buffer, due to incorrect patch applied to the third party code from libmagic, incorrect function may be used to free allocated memory, which may lead to heap corruption.

A vulnerability was found in php. This issue occurs due to memory corruption in the finfo_buffer() function and a bad patch of the libmagic library. This flaw allows an attacker or malicious actor to execute a heap buffer overflow successfully, causing a memory crash.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6phpNot affected
Red Hat Enterprise Linux 7phpNot affected
Red Hat Enterprise Linux 8php:7.4/phpNot affected
Red Hat Enterprise Linux 8php:8.0/phpNot affected
Red Hat Enterprise Linux 9phpNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=2107018php: heap buffer overflow in finfo_buffer

EPSS

Процентиль: 34%
0.0013
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.7
ubuntu
почти 3 года назад

In PHP versions 8.1.x below 8.1.8, when fileinfo functions, such as finfo_buffer, due to incorrect patch applied to the third party code from libmagic, incorrect function may be used to free allocated memory, which may lead to heap corruption.

CVSS3: 7.7
nvd
почти 3 года назад

In PHP versions 8.1.x below 8.1.8, when fileinfo functions, such as finfo_buffer, due to incorrect patch applied to the third party code from libmagic, incorrect function may be used to free allocated memory, which may lead to heap corruption.

CVSS3: 9.8
msrc
9 месяцев назад

Описание отсутствует

CVSS3: 7.7
debian
почти 3 года назад

In PHP versions 8.1.x below 8.1.8, when fileinfo functions, such as fi ...

CVSS3: 9.8
github
почти 3 года назад

In PHP versions 8.1.x below 8.1.8, when fileinfo functions, such as finfo_buffer, due to incorrect patch applied to the third party code from libmagic, incorrect function may be used to free allocated memory, which may lead to heap corruption.

EPSS

Процентиль: 34%
0.0013
Низкий

7.5 High

CVSS3