9.8
CVSSv3

CVE-2022-31627

Published: 28/07/2022 Updated: 25/10/2022
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

In PHP versions 8.1.x below 8.1.8, when fileinfo functions, such as finfo_buffer, due to incorrect patch applied to the third party code from libmagic, incorrect function may be used to free allocated memory, which may lead to heap corruption.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

php php

Vendor Advisories

Debian Bug report logs - #1016972 php81: CVE-2022-31627 Package: src:php81; Maintainer for src:php81 is Debian PHP Maintainers <team+pkg-php@trackerdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Wed, 10 Aug 2022 20:06:04 UTC Severity: grave Tags: security, upstream Forwarded to bu ...
ALAS-2022-243 Amazon Linux 2022 Security Advisory: ALAS-2022-243 Advisory Release Date: 2022-12-06 16:44 Pacific ...