In PHP versions 8.1.x below 8.1.8, when fileinfo functions, such as finfo_buffer, due to incorrect patch applied to the third party code from libmagic, incorrect function may be used to free allocated memory, which may lead to heap corruption.
References
Link | Resource |
---|---|
https://bugs.php.net/bug.php?id=81723 | Exploit Issue Tracking Patch Third Party Advisory |
https://security.gentoo.org/glsa/202209-20 | Third Party Advisory |
https://security.netapp.com/advisory/ntap-20220826-0008/ | Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: php
Published: 2022-07-05T00:00:00
Updated: 2022-09-29T16:06:53
Reserved: 2022-05-25T00:00:00
Link: CVE-2022-31627
JSON object: View
NVD Information
Status : Analyzed
Published: 2022-07-28T06:15:07.547
Modified: 2022-10-25T19:45:51.713
Link: CVE-2022-31627
JSON object: View
Redhat Information
No data.