← Back

CVE-2022-31630

nvd nist
Published: Nov 14, 2022Modified: Jun 17, 2026

JSON object

Loading...
7.1
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
Exploitability: 1.8 / Impact: 5.2
Source: NVD

Description

In PHP versions prior to 7.4.33, 8.0.25 and 8.1.12, when using imageloadfont() function in gd extension, it is possible to supply a specially crafted font file, such as if the loaded font is used with imagechar() function, the read outside allocated buffer will be used. This can lead to crashes or disclosure of confidential information. 

Affected (3)

Products: Php: Php
1 product
Php
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Php
From 7.4.0 to 7.4.33
From 8.0.0 to 8.0.25
From 8.1.0 to 8.1.12

References (2)

Source: security@php.net
ExploitIssue TrackingPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingPatchVendor Advisory

Timeline

No history available yet.