Description
In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the phar uncompressor code would recursively uncompress "quines" gzip files, resulting in an infinite loop.
No analysis available yet.
Remediation
Vendor Solution
Upgrade to PHP 7.4.31, 8.0.24, or 8.1.11.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3243-1 | php7.3 security update |
Debian DSA |
DSA-5277-1 | php7.4 security update |
EUVD |
EUVD-2022-53080 | In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the phar uncompressor code would recursively uncompress "quines" gzip files, resulting in an infinite loop. |
Ubuntu USN |
USN-5717-1 | PHP vulnerabilities |
Ubuntu USN |
USN-5905-1 | PHP vulnerabilities |
References
History
Tue, 20 May 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: php
Published:
Updated: 2025-05-20T20:24:57.733Z
Reserved: 2022-05-25T00:00:00.000Z
Link: CVE-2022-31628
Updated: 2024-08-03T07:25:59.512Z
Status : Modified
Published: 2022-09-28T23:15:09.497
Modified: 2024-11-21T07:04:53.293
Link: CVE-2022-31628
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN