CVE-2022-31627: Heap buffer overflow in finfo_buffer
Published Jul 5, 2022
·Updated
In PHP versions 8.1.x below 8.1.8, when fileinfo functions, such as finfobuffer, due to incorrect patch applied to the third party code from libmagic, incorrect function may be used to free allocated memory, which may lead to heap corruption.
Other sources
Fixed bug (Heap buffer overflow in finfobuffer). (CVE-2022-31627)
— PHP
Affected Software
2 affected componentsFixes available
PHP PHP>=8.1.0<8.1.8
PHP PHP<8.1.8
8.1.8
Remediation
Patch Available
Event History
Jul 7, 2022
CVE Published
via PHP·12:00 AM
Jul 28, 2022
CVE Published
via MITRE·05:50 AM
Data Sourced
via MITRE·05:50 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-31627?
CVE-2022-31627 is a fixed bug in PHP versions 8.1.x below 8.1.8.
2
What is the severity of CVE-2022-31627?
CVE-2022-31627 has a severity level of critical with a score of 9.8.
3
How does CVE-2022-31627 affect PHP?
CVE-2022-31627 can lead to heap corruption in PHP versions 8.1.x below 8.1.8 when using fileinfo functions.
4
How can I fix CVE-2022-31627?
To fix CVE-2022-31627, upgrade PHP to version 8.1.8 or above.
5
Where can I find more information about CVE-2022-31627?
You can find more information about CVE-2022-31627 at the following references: [link1], [link2], [link3].