CVE-2022-31627

In PHP versions 8.1.x below 8.1.8, when fileinfo functions, such as finfo_buffer, due to incorrect patch applied to the third party code from libmagic, incorrect function may be used to free allocated memory, which may lead to heap corruption.
References
Link Resource
https://bugs.php.net/bug.php?id=81723 Exploit Issue Tracking Patch Third Party Advisory
https://security.gentoo.org/glsa/202209-20 Third Party Advisory
https://security.netapp.com/advisory/ntap-20220826-0008/ Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:php:php:*:*:*:*:*:*:*:*

History

25 Oct 2022, 19:45

Type Values Removed Values Added
References
  • (GENTOO) https://security.gentoo.org/glsa/202209-20 - Third Party Advisory
References (CONFIRM) https://security.netapp.com/advisory/ntap-20220826-0008/ - (CONFIRM) https://security.netapp.com/advisory/ntap-20220826-0008/ - Third Party Advisory

26 Aug 2022, 15:15

Type Values Removed Values Added
References
  • (CONFIRM) https://security.netapp.com/advisory/ntap-20220826-0008/ -

03 Aug 2022, 23:19

Type Values Removed Values Added
CPE cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
References (MISC) https://bugs.php.net/bug.php?id=81723 - (MISC) https://bugs.php.net/bug.php?id=81723 - Exploit, Issue Tracking, Patch, Third Party Advisory
CWE CWE-787

28 Jul 2022, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-07-28 06:15

Updated : 2024-02-04 22:51


NVD link : CVE-2022-31627

Mitre link : CVE-2022-31627

CVE.ORG link : CVE-2022-31627


JSON object : View

Products Affected

php

  • php
CWE
CWE-787

Out-of-bounds Write

CWE-590

Free of Memory not on the Heap