CVE-2022-31628


phar wrapper can occur dos when using quine gzip file

In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the phar uncompressor code would recursively uncompress "quines" gzip files, resulting in an infinite loop.



We have discovered 1,052,163 live websites that are affected by CVE-2022-31628.

Contact us to get more info




Affected Software

Product  PHP
Category Programming Languages
Vulnerable Versions
  • from 7.4 before 7.4.31
  • from 8 before 8.0.24
  • from 8.1 before 8.1.11
Total Vulnerable Versions507
Vulnerable Domains1,052,163 live websites (8.70% of PHP install base)


Common Weakness Enumeration


CWE-674 Uncontrolled Recursion


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2022-31628 and the relative popularity of websites


Details

  • Published - Sep 27, 2022
  • Updated - Dec 15, 2022

Credits

  • reported by ohseungju5 at gmail dot com





Countries

United States371,796 websites



France222,333 websites
Russia47,434 websites
Japan44,801 websites
Germany35,101 websites
GB24,216 websites
Netherlands24,045 websites
Canada22,330 websites
Italy20,042 websites
Spain19,789 websites

TLDs

.com503,884 websites
.fr99,168 websites
.org59,605 websites
.ru39,008 websites
.net33,225 websites
.de21,442 websites
.nl18,726 websites
.it15,331 websites
.com.br14,838 websites
.pl14,353 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2022-31628 through included software libraries and plugins.



References


Websites affected by CVE-2022-31628

Top websites that are affected by CVE-2022-31628. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***.*****.pl Poland*,***
***.*****.pm Saint Pierreand Miquelon*,***
*******.com Germany*,***
****.org GB*,***
***************.org United States*,***
**********.org United States*,***
******.org United States*,***
***.**********.org United States*,***
******.com France*,***
**********.com France*,***
See full domain list