CVE-2022-31630

Updated: 2024-11-21 22:27:39.328399

Description:

In PHP versions prior to 7.4.33, 8.0.25 and 8.1.12, when using imageloadfont() function in gd extension, it is possible to supply a specially crafted font file, such as if the loaded font is used with imagechar() function, the read outside allocated buffer will be used. This can lead to crashes or disclosure of confidential information. 


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0
CVSS Version 3.x HIGH 7.1000000000000005

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

Debian 10 php 7.1 7.1 HIGH Needs Triage 2025-04-28 18:53:59
Debian 10 php 7.3 7.1 HIGH Needs Triage 2025-04-28 18:54:02
Debian 10 php 7.4 7.1 HIGH Needs Triage 2025-04-28 18:54:03
Debian 10 php 5.6 7.1 HIGH Needs Triage 2025-04-28 18:53:57
Debian 10 php 7.0 7.1 HIGH Needs Triage 2025-04-28 18:53:58
Debian 10 php 7.2 7.1 HIGH Needs Triage 2025-04-28 18:54:01
Debian 10 php 8.0 7.1 HIGH Needs Triage 2025-04-28 18:54:04
Debian 10 php 8.1 7.1 HIGH Needs Triage 2025-04-28 18:54:06
Debian 10 php 8.2 7.1 HIGH Needs Triage 2025-04-28 18:54:07
Debian 11 php 5.6 7.1 HIGH Needs Triage 2025-04-28 18:54:08
Total: 124