CVE-2022-31627


Heap buffer overflow in finfo_buffer

In PHP versions 8.1.x below 8.1.8, when fileinfo functions, such as finfo_buffer, due to incorrect patch applied to the third party code from libmagic, incorrect function may be used to free allocated memory, which may lead to heap corruption.



We have discovered 63,448 live websites that are affected by CVE-2022-31627.

Contact us to get more info




Affected Software

Product  PHP
Category Programming Languages
Vulnerable Versions
  • from 8.1 before 8.1.8
Total Vulnerable Versions507
Vulnerable Domains63,448 live websites (0.52% of PHP install base)


Common Weakness Enumeration


CWE-590 Free of Memory not on the Heap


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2022-31627 and the relative popularity of websites


Details

  • Published - Jul 5, 2022
  • Updated - Sep 29, 2022

Credits

  • reported by xd4rker at gmail dot com





Countries

United States16,479 websites



France25,768 websites
Germany2,507 websites
Sweden2,350 websites
Russia2,128 websites
Belgium1,283 websites
Poland1,279 websites
Italy1,243 websites
GB1,239 websites
Spain1,173 websites

TLDs

.com26,978 websites
.fr11,680 websites
.org3,646 websites
.se1,981 websites
.ru1,841 websites
.net1,745 websites
.de1,672 websites
.be1,441 websites
.pl980 websites
.it950 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2022-31627 through included software libraries and plugins.



References


Websites affected by CVE-2022-31627

Top websites that are affected by CVE-2022-31627. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***************.com Singapore*,***
*********.ru Russia**,***
***.********.com United States**,***
*****.********.com United States**,***
*******.com United States**,***
***.*******.info Austria**,***
****.com Belgium**,***
***.org United States**,***
*****.org Russia**,***
*****.gov United States**,***
See full domain list