OSV-2022-863

    Dashboard / Vulnerabilities / OSV-2022-863

    OSV-2022-863

    Published: 8 Sept 2022Last Modified: 15 Sept 2022

    Summary: Heap-use-after-free in user_wrapper_opendir

    Details: OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=51047 ``` Crash type: Heap-use-after-free READ 10 Crash state: user_wrapper_opendir _php_stream_opendir _php_do_opendir ```

    Affected packages

    Package

    Name: php

    Purl: pkg:generic/php

    Affected ranges

    Type: GIT

    Events:

    Introduced- cae80ef552c7da262e8070264ccf778454477a08

    Affected versions

    php-8.1.0
    php-8.1.2RC1
    php-8.1.3
    php-8.1.4RC1
    php-8.1.7RC1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    OSV-2022-863 | CVE-DB