ZeroHour

CVE-2022-31628

CVSS 3.1
5.5 medium
EPSS
<1%p47
Published
()
Modified
Description

In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the phar uncompressor code would recursively uncompress "quines" gzip files, resulting in an infinite loop.

Vendors
phpfedoraprojectdebian
Products
php, fedora, debian linux
Weakness
CWE-674, CWE-835
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.