7.1
CVSSv3

CVE-2022-31630

Published: 14/11/2022 Updated: 02/04/2024
CVSS v3 Base Score: 7.1 | Impact Score: 5.2 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

In PHP versions before 7.4.33, 8.0.25 and 8.1.12, when using imageloadfont() function in gd extension, it is possible to supply a specially crafted font file, such as if the loaded font is used with imagechar() function, the read outside allocated buffer will be used. This can lead to crashes or disclosure of confidential information. 

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

php php

Vendor Advisories

Several security issues were fixed in PHP ...
Synopsis Moderate: php:80 security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for the php:80 module is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as ...
Synopsis Moderate: php:81 security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for the php:81 module is now available for Red Hat Enterprise Linux 9Red Hat Product Security has rated this update as ...
Multiple security issues were discovered in PHP, a widely-used open source general purpose scripting language which could result in denial of service, information disclosure, insecure cooking handling or potentially the execution of arbitrary code For the stable distribution (bullseye), these problems have been fixed in version 7433-1+deb11u1 W ...
In PHP versions prior to 7433, 8025 and 8212, when using imageloadfont() function in gd extension, it is possible to supply a specially crafted font file, such as if the loaded font is used with imagechar() function, the read outside allocated buffer will be used This can lead to crashes or disclosure of confidential information (CVE-2022-3 ...
In PHP versions prior to 7433, 8025 and 8212, when using imageloadfont() function in gd extension, it is possible to supply a specially crafted font file, such as if the loaded font is used with imagechar() function, the read outside allocated buffer will be used This can lead to crashes or disclosure of confidential information (CVE-2022-3 ...
Description<!----> This CVE is under investigation by Red Hat Product Security ...
ALAS-2022-243 Amazon Linux 2022 Security Advisory: ALAS-2022-243 Advisory Release Date: 2022-12-06 16:44 Pacific ...