CVE-2022-31625

Freeing unallocated memory in php_pgsql_free_params()

In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when using Postgres database extension, supplying invalid parameters to the parametrized query may lead to PHP attempting to free memory using uninitialized data as pointers. This could lead to RCE vulnerability or denial of service.


We have discovered 252,271 live websites that are affected by CVE-2022-31625.

Run a Free Instant Scan




Affected Software

Product  PHP
Category Programming Languages
Vulnerable Domains252,271 live websites (3.46% of PHP install base)
Vulnerable Versions
  • from 7.4 through 7.4.30
  • from 8 through 8.0.20
  • from 8.1 through 8.1.7
Vulnerable Versions Count55 versions ( 11% of all versions)


Common Weakness Enumeration

CWE-590 Free of Memory not on the Heap



Details

  • Published - Jun 16, 2022
  • Updated - Sep 16, 2024

Credits

  • c dot fol at ambionics dot io

Website Distribution by Country

Number of websites using CVE-2022-31625
United States42,222 websites



France112,038 websites
Russia10,171 websites
Germany9,000 websites
Japan6,885 websites
Brazil5,902 websites
Poland5,643 websites
Netherlands5,101 websites
China5,099 websites
Italy4,987 websites

Website Distribution by TLD

Number of websites using CVE-2022-31625
.com98,019 websites
.fr46,872 websites
.org10,659 websites
.ru8,897 websites
.net7,369 websites
.be5,690 websites
.de5,371 websites
.pl5,357 websites
.it5,049 websites
.com.br5,034 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2022-31625

Top websites that are affected by CVE-2022-31625. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.pl Poland*,***
*********.org United States*,***
**********.org United States*,***
******.com France*,***
*******.pro Russia*,***
****.**********.***.uk GB*,***
***************.com Singapore*,***
******.at Austria*,***
******.com France*,***
**.***.ca Canada**,***
See full domain list

FAQ

CVE-2022-31625 is Free of Memory not on the Heap in PHP
A total of 252,271 websites have been identified as vulnerable to CVE-2022-31625, based on global website indexing conducted by WebTechSurvey.
The PHP is affected by the CVE-2022-31625 vulnerability.
PHP versions up to 8.1.7 are vulnerable to CVE-2022-31625.
CVE-2022-31625 is resolved in version 8.1.7 of PHP.