In PHP versions 8.1.x below 8.1.8, when fileinfo functions, such as finfo_buffer, due to incorrect patch applied to the third party code from libmagic, incorrect function may be used to free allocated memory, which may lead to heap corruption.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: php

Published: 2022-07-28T05:50:09.522067Z

Updated: 2024-09-16T21:02:46.605Z

Reserved: 2022-05-25T00:00:00

Link: CVE-2022-31627

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-07-28T06:15:07.547

Modified: 2022-10-25T19:45:51.713

Link: CVE-2022-31627

cve-icon Redhat

Severity : Low

Publid Date: 2022-07-08T00:00:00Z

Links: CVE-2022-31627 - Bugzilla