CVE-2022-31625

Updated: 2024-11-30 02:13:12.451998

Description:

In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when using Postgres database extension, supplying invalid parameters to the parametrized query may lead to PHP attempting to free memory using uninitialized data as pointers. This could lead to RCE vulnerability or denial of service.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x MEDIUM 6.8
CVSS Version 3.x HIGH 8.1

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

CentOS 6 ELS php 5.3.3 8.1 HIGH Released CLSA-2022:1658171149 2022-08-01 14:03:18
CentOS 7 ELS php 5.4.16 8.1 HIGH Released CLSA-2024:1706700142 2024-02-19 10:09:30
CentOS 8.4 ELS php 7.4.6 8.1 HIGH Released CLSA-2022:1656958574 2022-07-04 14:43:43
CentOS 8.5 ELS php 7.4.19 8.1 HIGH Released CLSA-2022:1656958778 2022-07-04 14:43:43
CloudLinux 6 ELS php 5.3.3 8.1 HIGH Released CLSA-2022:1658168300 2022-08-01 13:07:59
Oracle Linux 6 ELS php 5.3.3 8.1 HIGH Released CLSA-2022:1658171795 2022-07-18 16:26:31
Ubuntu 16.04 ELS php 7.0.33 8.1 HIGH Released CLSA-2022:1657182029 2022-07-07 06:30:43
Ubuntu 18.04 ELS php 7.2.24-0 8.1 HIGH Already Fixed 2023-06-29 14:06:38