VulnerabilityModified
CVE-2022-31628
In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the phar uncompressor code would recursively uncompress "quines" gzip files, resulting in an infinite loop.
MEDIUM 5.5EPSS 0.61%
Does this matter?
Lower severity and a low EPSS score (0.61%). Track it; it rarely justifies an emergency change on its own.
Description
In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the phar uncompressor code would recursively uncompress "quines" gzip files, resulting in an infinite loop.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.61% probability · 47th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-674, CWE-835
- Affected
- php/php · fedoraproject/fedora · debian/debian linux
- Source
- security@php.net
References
- https://bugs.php.net/bug.php?id=81726Permissions Required, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/12/msg00030.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2L5SUVYGAKSWODUQPZFBUB3AL6E6CSEV/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VI3E6A3ZTH2RP7OMLJHSVFIEQBIFM6RF/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XNIEABBH5XCXLFWWZYIDE457SPEDZTXV/
- https://security.gentoo.org/glsa/202211-03Third Party Advisory
- https://security.netapp.com/advisory/ntap-20221209-0001/Third Party Advisory
- https://www.debian.org/security/2022/dsa-5277Third Party Advisory
- https://bugs.php.net/bug.php?id=81726Permissions Required, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/12/msg00030.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2L5SUVYGAKSWODUQPZFBUB3AL6E6CSEV/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VI3E6A3ZTH2RP7OMLJHSVFIEQBIFM6RF/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XNIEABBH5XCXLFWWZYIDE457SPEDZTXV/
- https://security.gentoo.org/glsa/202211-03Third Party Advisory
- https://security.netapp.com/advisory/ntap-20221209-0001/Third Party Advisory
- https://www.debian.org/security/2022/dsa-5277Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.