Description
In PHP versions 8.1.x below 8.1.8, when fileinfo functions, such as finfo_buffer, due to incorrect patch applied to the third party code from libmagic, incorrect function may be used to free allocated memory, which may lead to heap corruption.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-53079 | In PHP versions 8.1.x below 8.1.8, when fileinfo functions, such as finfo_buffer, due to incorrect patch applied to the third party code from libmagic, incorrect function may be used to free allocated memory, which may lead to heap corruption. |
Ubuntu USN |
USN-5530-1 | PHP vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: php
Published:
Updated: 2024-09-16T21:02:46.605Z
Reserved: 2022-05-25T00:00:00.000Z
Link: CVE-2022-31627
No data.
Status : Modified
Published: 2022-07-28T06:15:07.547
Modified: 2024-11-21T07:04:53.160
Link: CVE-2022-31627
OpenCVE Enrichment
No data.
EUVD
Ubuntu USN