CVE-2022-31627

In PHP versions 8.1.x below 8.1.8, when fileinfo functions, such as finfo_buffer, due to incorrect patch applied to the third party code from libmagic, incorrect function may be used to free allocated memory, which may lead to heap corruption.
References
Link Resource
https://bugs.php.net/bug.php?id=81723 Exploit Issue Tracking Patch Third Party Advisory
https://security.netapp.com/advisory/ntap-20220826-0008/ Third Party Advisory
https://security.gentoo.org/glsa/202209-20 Third Party Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:php:php:*:*:*:*:*:*:*:*

Information

Published : 2022-07-27 23:15

Updated : 2022-10-25 12:45


NVD link : CVE-2022-31627

Mitre link : CVE-2022-31627


JSON object : View

CWE
CWE-787

Out-of-bounds Write

Advertisement

dedicated server usa

Products Affected

php

  • php