ZeroHour

CVE-2022-31627

PoC
CVSS 3.1
9.8 critical
EPSS
2%p80
Published
()
Modified
Description

In PHP versions 8.1.x below 8.1.8, when fileinfo functions, such as finfo_buffer, due to incorrect patch applied to the third party code from libmagic, incorrect function may be used to free allocated memory, which may lead to heap corruption.

Vendors
php
Products
php
Weakness
CWE-590, CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.