Vulnerability CVE-2022-31628: Information

Description

In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the phar uncompressor code would recursively uncompress "quines" gzip files, resulting in an infinite loop.

Severity: MEDIUM (5.5) Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Published: Sept. 29, 2022
Modified: Nov. 7, 2023
Error type identifier: CWE-835

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
php7p107.4.32-alt17.4.33-alt1ALT-PU-2022-2810-1307829Fixed
php7p10_e2k7.4.32-alt17.4.33-alt1ALT-PU-2022-6520-1-Fixed
php7c10f17.4.32-alt17.4.33-alt1ALT-PU-2022-2810-1307829Fixed
php7c9f27.4.32-alt17.4.33-alt1ALT-PU-2022-2755-1307875Fixed
php7-curlp10_e2k7.4.32-alt17.4.33-alt1ALT-PU-2022-6521-1-Fixed
php7-gdp10_e2k7.4.32-alt17.4.33-alt1ALT-PU-2022-6522-1-Fixed
php7-intlp10_e2k7.4.32-alt17.4.33-alt1ALT-PU-2022-6528-1-Fixed
php7-opcachep10_e2k7.4.32-alt1.27.4.33-alt1.2ALT-PU-2022-6529-1-Fixed
php7-opensslp10_e2k7.4.32-alt17.4.33-alt1ALT-PU-2022-6523-1-Fixed
php7-pdo_mysqlp10_e2k7.4.32-alt17.4.33-alt1ALT-PU-2022-6524-1-Fixed
php7-pgsqlp10_e2k7.4.32-alt17.4.33-alt1ALT-PU-2022-6525-1-Fixed
php7-tidyp10_e2k7.4.32-alt17.4.33-alt1ALT-PU-2022-6531-1-Fixed
php7-xmlrpcp10_e2k7.4.32-alt17.4.33-alt1ALT-PU-2022-6530-1-Fixed
php7-xslp10_e2k7.4.32-alt1.17.4.33-alt1.1ALT-PU-2022-6527-1-Fixed
php7-zipp10_e2k7.4.32-alt17.4.33-alt1ALT-PU-2022-6526-1-Fixed
php8.0p108.0.24-alt18.0.30-alt1ALT-PU-2022-2827-1307752Fixed
php8.0p10_e2k8.0.24-alt18.0.30-alt1ALT-PU-2022-6519-1-Fixed
php8.0c10f18.0.24-alt18.0.30-alt1ALT-PU-2022-2827-1307752Fixed
php8.1sisyphus8.1.11-alt18.1.28-alt1ALT-PU-2022-2698-1307626Fixed
php8.1sisyphus_e2k8.1.11-alt18.1.28-alt1ALT-PU-2022-6346-1-Fixed
php8.1sisyphus_riscv648.1.11-alt18.1.28-alt1ALT-PU-2022-6338-1-Fixed
php8.1p108.1.11-alt18.1.28-alt1ALT-PU-2022-2767-1307734Fixed
php8.1p10_e2k8.1.11-alt18.1.28-alt1ALT-PU-2022-6517-1-Fixed
php8.1c10f18.1.11-alt18.1.28-alt1ALT-PU-2022-2767-1307734Fixed
php8.1c9f28.1.11-alt18.1.16-alt1ALT-PU-2022-3022-1307765Fixed
php8.1p118.1.11-alt18.1.28-alt1ALT-PU-2022-2698-1307626Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
      Start including
      8.1.0
      End excliding
      8.1.11

      cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
      Start including
      8.0.0
      End excliding
      8.0.24

      cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
      End excliding
      7.4.31

      Configuration 2

      cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*

      cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*

      cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*

      Configuration 3

      cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

      cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*