CVE-2022-31627
Summary
| CVE | CVE-2022-31627 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-07-28 06:15:00 UTC |
| Updated | 2022-10-25 19:45:00 UTC |
| Description | In PHP versions 8.1.x below 8.1.8, when fileinfo functions, such as finfo_buffer, due to incorrect patch applied to the third party code from libmagic, incorrect function may be used to free allocated memory, which may lead to heap corruption. |
Risk And Classification
Problem Types: CWE-787
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| PHP: Multiple Vulnerabilities (GLSA 202209-20) — Gentoo security | GENTOO | security.gentoo.org | |
| PHP :: Sec Bug #81723 :: Heap buffer overflow in finfo_buffer | MISC | bugs.php.net | |
| CVE-2022-31627 PHP Vulnerability in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: reported by xd4rker at gmail dot com
Legacy QID Mappings
- 150558 PHP Heap Buffer Overflow Vulnerability (CVE-2022-31627)
- 198871 Ubuntu Security Notification for Hypertext Preprocessor (PHP) Vulnerability (USN-5530-1)
- 282942 Fedora Security Update for Hypertext Preprocessor (PHP) (FEDORA-2022-ec0491574d)
- 296084 Oracle Solaris 11.4 Support Repository Update (SRU) 50.126.3 Missing (CPUOCT2022)
- 354414 Amazon Linux Security Advisory for php8.1 : ALAS2022-2022-243
- 354548 Amazon Linux Security Advisory for php8.1 : ALAS-2022-243
- 355222 Amazon Linux Security Advisory for php8.1 : ALAS2023-2023-081
- 38882 Hypertext Preprocessor (PHP) Heap Buffer Overflow Vulnerability (81723)
- 710633 Gentoo Linux Hypertext Preprocessor (PHP) Multiple Vulnerabilities (GLSA 202209-20)
- 905175 Common Base Linux Mariner (CBL-Mariner) Security Update for Hypertext Preprocessor (PHP) (12605)