In PHP versions 8.1.x below 8.1.8, when fileinfo...
Critical severity
Unreviewed
Published
Jul 29, 2022
to the GitHub Advisory Database
•
Updated Jan 28, 2023
Description
Published by the National Vulnerability Database
Jul 28, 2022
Published to the GitHub Advisory Database
Jul 29, 2022
Last updated
Jan 28, 2023
In PHP versions 8.1.x below 8.1.8, when fileinfo functions, such as finfo_buffer, due to incorrect patch applied to the third party code from libmagic, incorrect function may be used to free allocated memory, which may lead to heap corruption.
References