UBUNTU-CVE-2022-31631
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-31631
UBUNTU-CVE-2022-31631
Summary:
Details: In PHP versions 8.0.* before 8.0.27, 8.1.* before 8.1.15, 8.2.* before 8.2.2 when using PDO::quote() function to quote user-supplied data for SQLite, supplying an overly long string may cause the driver to incorrectly quote the data, which may further lead to SQL injection vulnerabilities.
References: https://ubuntu.com/security/CVE-2022-31631, https://github.com/php/php-src/commit/921b6813da3237a83e908998483f46ae3d8bacba, https://github.com/php/php-src/commit/a6a80eefe0413c91acd922bc58590a4db7979af0, https://ubuntu.com/security/notices/USN-5818-1, https://ubuntu.com/security/notices/USN-5905-1, https://www.cve.org/CVERecord?id=CVE-2022-31631
Affected packages
Package
Name: php5
Purl: pkg:deb/ubuntu/[email protected]+dfsg-1ubuntu4.29+esm16?arch=source&distro=esm-infra-legacy/trusty
Affected ranges
Type: ECOSYSTEM
Events:
