Vulnerability Description
In PHP versions 8.1.x below 8.1.8, when fileinfo functions, such as finfo_buffer, due to incorrect patch applied to the third party code from libmagic, incorrect function may be used to free allocated memory, which may lead to heap corruption.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Php | Php | >= 8.1.0, < 8.1.8 |
Related Weaknesses (CWE)
References
- https://bugs.php.net/bug.php?id=81723ExploitIssue TrackingPatch
- https://security.gentoo.org/glsa/202209-20Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220826-0008/Third Party Advisory
- https://bugs.php.net/bug.php?id=81723ExploitIssue TrackingPatch
- https://security.gentoo.org/glsa/202209-20Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220826-0008/Third Party Advisory
FAQ
What is CVE-2022-31627?
CVE-2022-31627 is a vulnerability with a CVSS score of 7.7 (HIGH). In PHP versions 8.1.x below 8.1.8, when fileinfo functions, such as finfo_buffer, due to incorrect patch applied to the third party code from libmagic, incorrect function may be used to free allocated...
How severe is CVE-2022-31627?
CVE-2022-31627 has been rated HIGH with a CVSS base score of 7.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-31627?
Check the references section above for vendor advisories and patch information. Affected products include: Php Php.