CVE-2022-31625
php7.4 - security update
8.1
HIGH
CVSS 3.1
EPSS 1.5%
Description
In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when using Postgres database extension, supplying invalid parameters to the parametrized query may lead to PHP attempting to free memory using uninitialized data as pointers. This could lead to RCE vulnerability or denial of service.
How to fix CVE-2022-31625
To remediate CVE-2022-31625, upgrade the affected package to a fixed version below.
- —upgrade to 7.4.30 or later
- —upgrade to 7.4.30 or later
- —upgrade to 7.4.30 or later
- —upgrade to 7.4.30-1+deb11u1 or later
- —upgrade to 7.4.30-1+deb11u1 or later
Is CVE-2022-31625 being exploited?
Low — EPSS is 1.5%, meaning exploitation activity has not been observed at scale.
Affected packages (5)
- >= 7.4.0, < 7.4.30, >= 8.0.0, < 8.0.20, >= 8.1.0, < 8.1.7
- >= 7.4.0, < 7.4.30, >= 8.0.0, < 8.0.20, >= 8.1.0, < 8.1.7
- >= 7.4.0, < 7.4.30, >= 8.0.0, < 8.0.20, >= 8.1.0, < 8.1.7
- from 0, < 7.4.30-1+deb11u1
- from 0, < 7.4.30-1+deb11u1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.1 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |