QID 356076

QID 356076: Amazon Linux Security Advisory for Hypertext Preprocessor (PHP) : ALASPHP8.0-2023-006

A vulnerability was found in php due to an uninitialized array in pg_query_params() function.
When using the postgres database extension, supplying invalid parameters to the parameterized query may lead to php attempting to free memory, using uninitialized data as pointers.
This flaw allows a remote attacker with the ability to control query parameters to execute arbitrary code on the system or may cause a denial of service. (
( CVE-2022-31625) a buffer overflow vulnerability was found in php when processing passwords in mysqlnd/pdo in mysqlnd_wireprotocol.c.
When using the pdo_mysql extension with mysqlnd driver, if the third party is allowed to supply a password to the host for the connection, a password of excessive length can trigger a buffer overflow in php.
This flaw allows a remote attacker to pass a password (with an excessive length) via pdo to the mysql server, triggering arbitrary code execution on the target system. (
( CVE-2022-31626)



Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.

Successful exploitation of this vulnerability could lead to a securitybreach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Please refer to Amazon advisory: ALASPHP8.0-2023-006 for affected packages and patching details, or update with your package manager.
    Vendor References

    CVEs related to QID 356076

    Software Advisories
    Advisory ID Software Component Link
    ALASPHP8.0-2023-006 amazon linux 2 URL Logo alas.aws.amazon.com/AL2/ALASPHP8.0-2023-006.html