PT-2022-4484 · Php+10 · Php+10

Charles Fol

·

Published

2022-02-27

·

Updated

2025-08-11

·

CVE-2022-31625

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions PHP versions 7.4.x through 7.4.29 PHP versions 8.0.x through 8.0.19 PHP versions 8.1.x through 8.1.6
Description The issue is related to the pg query params() function in PHP's Postgres database extension, where supplying invalid parameters to a parametrized query may cause PHP to attempt to free memory using uninitialized data as pointers. This could lead to remote code execution or denial of service. The vulnerability can be exploited by a remote attacker, potentially allowing them to execute arbitrary code.
Recommendations For PHP versions 7.4.x through 7.4.29, update to version 7.4.30 or later. For PHP versions 8.0.x through 8.0.19, update to version 8.0.20 or later. For PHP versions 8.1.x through 8.1.6, update to version 8.1.7 or later.

Exploit

Fix

DoS

RCE

Access of Uninitialized Pointer

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022:6158
ALSA-2022:7624
ALSA-2022:8197
ALT-PU-2022-2064
ALT-PU-2022-2065
ALT-PU-2022-2075
ALT-PU-2022-2098
ALT-PU-2022-2100
ALT-PU-2022-2112
ALT-PU-2022-2117
ALT-PU-2022-2119
BDU:2022-05351
BIT-LIBPHP-2022-31625
BIT-PHP-2022-31625
BIT-PHP-MIN-2022-31625
CESA-2022_6158
CESA-2022_7624
CVE-2022-31625
DLA-3243-1
DSA-5179-1
MGASA-2022-0234
OESA-2022-1721
OPENSUSE-SU-2022_2185-1
OPENSUSE-SU-2022_2275-1
OPENSUSE-SU-2022_2292-1
OPENSUSE-SU-2022_2303-1
OPENSUSE-SU-2022_3997-1
OPENSUSE-SU-2022_4067-1
OPENSUSE-SU-2022_4069-1
OPENSUSE-SU-2024:13267-1
RHSA-2022:5491
RHSA-2022:6158
RHSA-2022:7624
RHSA-2022:8197
RHSA-2022_6158
RHSA-2022_7624
RHSA-2022_8197
RLSA-2022:6158
RLSA-2022:7624
RLSA-2022:8197
SUSE-SU-2022:2161-1
SUSE-SU-2022:2183-1
SUSE-SU-2022:2185-1
SUSE-SU-2022:2275-1
SUSE-SU-2022:2292-1
SUSE-SU-2022:2303-1
SUSE-SU-2022:3997-1
SUSE-SU-2022:4067-1
SUSE-SU-2022:4068-1
SUSE-SU-2022:4069-1
USN-5479-1
USN-5479-2
USN-5479-3

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Php
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu