Security Advisory

CVE-2022-31628

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2022-09-28 22:25:09
Last updated 2025-05-20 20:24:57
Assigner php
State PUBLISHED

Description

In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the phar uncompressor code would recursively uncompress "quines" gzip files, resulting in an infinite loop.