Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-31630
HistoryNov 14, 2022 - 7:15 a.m.

Design/Logic Flaw

2022-11-1407:15:00
PRIOn knowledge base
www.prio-n.com
60
php
imageloadfont
gd extension
design flaw
logic flaw
vulnerability
disclosure
confidential information
nvd

7.8 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

34.3%

In PHP versions prior to 7.4.33, 8.0.25 and 8.2.12, when using imageloadfont() function in gd extension, it is possible to supply a specially crafted font file, such as if the loaded font is used with imagechar() function, the read outside allocated buffer will be used. This can lead to crashes or disclosure of confidential information.

CPENameOperatorVersion
phpge8.0.0
phplt8.0.25
phpge8.1.0
phplt8.1.12
phpge7.4.0
phplt7.4.33