Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-31630


In PHP versions prior to 7.4.33, 8.0.25 and 8.1.12, when using imageloadfont() function in gd extension, it is possible to supply a specially crafted font file, such as if the loaded font is used with imagechar() function, the read outside allocated buffer will be used. This can lead to crashes or disclosure of confidential information. 


Published

2022-11-14T07:15:09.467

Last Modified

2024-11-21T07:04:53.693

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-131
    CWE-190
  • Type: Primary
    CWE-125

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application php php < 7.4.33 Yes
Application php php < 8.0.25 Yes
Application php php < 8.1.12 Yes

References