Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-31630

Опубликовано: 14 нояб. 2022
Источник: ubuntu
Приоритет: medium
CVSS3: 6.5

Описание

In PHP versions prior to 7.4.33, 8.0.25 and 8.1.12, when using imageloadfont() function in gd extension, it is possible to supply a specially crafted font file, such as if the loaded font is used with imagechar() function, the read outside allocated buffer will be used. This can lead to crashes or disclosure of confidential information.

РелизСтатусПримечание
bionic

DNE

esm-infra-legacy/trusty

not-affected

esm-infra/focal

DNE

focal

DNE

jammy

DNE

kinetic

DNE

trusty

ignored

end of standard support
trusty/esm

not-affected

upstream

needs-triage

xenial

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

esm-infra/focal

DNE

esm-infra/xenial

not-affected

focal

DNE

jammy

DNE

kinetic

DNE

trusty

DNE

upstream

needs-triage

xenial

ignored

end of standard support

Показывать по

РелизСтатусПримечание
bionic

not-affected

esm-infra/bionic

not-affected

esm-infra/focal

DNE

focal

DNE

jammy

DNE

kinetic

DNE

trusty

DNE

upstream

needs-triage

xenial

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

esm-infra/focal

not-affected

7.4.3-4ubuntu2.15
focal

released

7.4.3-4ubuntu2.15
jammy

DNE

kinetic

DNE

trusty

DNE

upstream

needs-triage

xenial

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

released

8.1.12-1ubuntu2
esm-infra/focal

DNE

focal

DNE

jammy

released

8.1.2-1ubuntu2.8
kinetic

released

8.1.7-1ubuntu3.1
lunar

released

8.1.12-1ubuntu2
trusty

DNE

upstream

released

8.1.12
xenial

DNE

Показывать по

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
redhat
больше 2 лет назад

In PHP versions prior to 7.4.33, 8.0.25 and 8.1.12, when using imageloadfont() function in gd extension, it is possible to supply a specially crafted font file, such as if the loaded font is used with imagechar() function, the read outside allocated buffer will be used. This can lead to crashes or disclosure of confidential information. 

CVSS3: 6.5
nvd
больше 2 лет назад

In PHP versions prior to 7.4.33, 8.0.25 and 8.1.12, when using imageloadfont() function in gd extension, it is possible to supply a specially crafted font file, such as if the loaded font is used with imagechar() function, the read outside allocated buffer will be used. This can lead to crashes or disclosure of confidential information. 

CVSS3: 6.5
debian
больше 2 лет назад

In PHP versions prior to 7.4.33, 8.0.25 and 8.1.12, when using imagelo ...

CVSS3: 7.1
redos
больше 2 лет назад

Уязвимость PHP

CVSS3: 7.1
github
больше 2 лет назад

In PHP versions prior to 7.4.33, 8.0.25 and 8.2.12, when using imageloadfont() function in gd extension, it is possible to supply a specially crafted font file, such as if the loaded font is used with imagechar() function, the read outside allocated buffer will be used. This can lead to crashes or disclosure of confidential information.

6.5 Medium

CVSS3