Security Advisory

CVE-2022-31630

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2022-11-14 06:53:06
Last updated 2024-08-03 07:26:01
Assigner php
State PUBLISHED

Description

In PHP versions prior to 7.4.33, 8.0.25 and 8.1.12, when using imageloadfont() function in gd extension, it is possible to supply a specially crafted font file, such as if the loaded font is used with imagechar() function, the read outside allocated buffer will be used. This can lead to crashes or disclosure of confidential information.