CVE-2022-31626
In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when pdo_mysql extension with mysqlnd driver, if the third party is allowed to supply host to connect to and the password for the connection, password of excessive length can…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 58.1%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when pdo_mysql extension with mysqlnd driver, if the third party is allowed to supply host to connect to and the password for the connection, password of excessive length can trigger a buffer overflow in PHP, which can lead to a remote code execution vulnerability.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 58.12% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-120
- Affected
- php/php · debian/debian linux
- Source
- security@php.net
References
- https://bugs.php.net/bug.php?id=81719Exploit, Issue Tracking, Mailing List, Patch, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2022/12/msg00030.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3T4MMEEZYYAEHPQMZDFN44PHORJWJFZQ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZZTZQKRGEYJT5UB4FGG3MOE72SQUHSL4/
- https://security.gentoo.org/glsa/202209-20Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220722-0005/Third Party Advisory
- https://www.debian.org/security/2022/dsa-5179Third Party Advisory
- https://bugs.php.net/bug.php?id=81719Exploit, Issue Tracking, Mailing List, Patch, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2022/12/msg00030.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3T4MMEEZYYAEHPQMZDFN44PHORJWJFZQ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZZTZQKRGEYJT5UB4FGG3MOE72SQUHSL4/
- https://security.gentoo.org/glsa/202209-20Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220722-0005/Third Party Advisory
- https://www.debian.org/security/2022/dsa-5179Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.