QID 150558
Date Published: 2022-08-11
QID 150558: PHP Heap Buffer Overflow Vulnerability (CVE-2022-31627)
PHP is a programming language originally designed for use in web-based applications with HTML content. PHP supports a wide variety of platforms and is used by numerous web-based software applications.
In installed version of PHP, when fileinfo functions, such as finfo_buffer, due to incorrect patch applied to the third party code from libmagic, incorrect function may be used to free allocated memory, which may lead to heap corruption.
Affected Versions:
PHP versions 8.1.x prior to 8.1.7
QID Detection Logic (Unauthenticated):
This QID checks the HTTP Server header to see if the server is running a vulnerable version of PHP.
Successful exploitation of this vulnerability could allow a remote attacker to trigger Buffer Overflow and execute arbitrary code on the target system.
For more information please refer to Sec Bug 81723 .
- Sec Bug 81723 -
bugs.php.net/bug.php?id=81723
CVEs related to QID 150558
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Sec Bug 81723 |
|