Bug 1203867 - (CVE-2022-31628) VUL-0: CVE-2022-31628: php5,php72,php74,php8,php53,php7: uncontrolled recursion in the phar uncompressor while decompressing "quines" gzip files
(CVE-2022-31628)
VUL-0: CVE-2022-31628: php5,php72,php74,php8,php53,php7: uncontrolled recursi...
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Normal
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/343794/
CVSSv3.1:SUSE:CVE-2022-31628:4.4:(AV:...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2022-09-29 07:27 UTC by Carlos López
Modified: 2022-11-29 13:49 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Carlos López 2022-09-29 07:27:58 UTC
CVE-2022-31628

In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the phar uncompressor code
would recursively uncompress "quines" gzip files, resulting in an infinite loop.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-31628
https://www.cve.org/CVERecord?id=CVE-2022-31628
http://www.cvedetails.com/cve/CVE-2022-31628/
https://bugs.php.net/bug.php?id=81726
Comment 1 Carlos López 2022-09-29 07:28:10 UTC
No details yet, upstream bug is private
Comment 2 Petr Gajdos 2022-10-03 08:27:49 UTC
The bug is public now.
Comment 6 Petr Gajdos 2022-10-03 14:42:39 UTC
Submitted for: 15sp4/php8, 15sp4,15sp2,15/php7, 12/php74,php72 and 11sp3/php53.

I believe all fixed.
Comment 8 Swamp Workflow Management 2022-10-19 16:22:36 UTC
SUSE-SU-2022:3661-1: An update that solves three vulnerabilities, contains two features and has one errata is now available.

Category: security (important)
Bug References: 1192050,1200772,1203867,1203870
CVE References: CVE-2021-21703,CVE-2022-31628,CVE-2022-31629
JIRA References: SLE-23639,SLE-24723
Sources used:
openSUSE Leap 15.4 (src):    apache2-mod_php8-8.0.24-150400.4.14.1, php8-8.0.24-150400.4.14.1, php8-embed-8.0.24-150400.4.14.1, php8-fastcgi-8.0.24-150400.4.14.1, php8-fpm-8.0.24-150400.4.14.1, php8-test-8.0.24-150400.4.14.1
SUSE Linux Enterprise Module for Web Scripting 15-SP4 (src):    apache2-mod_php8-8.0.24-150400.4.14.1, php8-8.0.24-150400.4.14.1, php8-embed-8.0.24-150400.4.14.1, php8-fastcgi-8.0.24-150400.4.14.1, php8-fpm-8.0.24-150400.4.14.1, php8-test-8.0.24-150400.4.14.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 11 Swamp Workflow Management 2022-11-01 14:30:37 UTC
SUSE-SU-2022:3830-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 1203867,1203870
CVE References: CVE-2022-31628,CVE-2022-31629
JIRA References: 
Sources used:
openSUSE Leap 15.4 (src):    php7-7.2.5-150000.4.98.2

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 13 Swamp Workflow Management 2022-11-11 20:51:30 UTC
SUSE-SU-2022:3957-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 1203867,1203870
CVE References: CVE-2022-31628,CVE-2022-31629
JIRA References: 
Sources used:
SUSE Linux Enterprise Software Development Kit 12-SP5 (src):    php72-7.2.5-1.84.1
SUSE Linux Enterprise Module for Web Scripting 12 (src):    php72-7.2.5-1.84.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 14 Swamp Workflow Management 2022-11-15 20:33:02 UTC
SUSE-SU-2022:3997-1: An update that fixes 8 vulnerabilities, contains one feature is now available.

Category: security (important)
Bug References: 1203867,1203870,1204577,1204979
CVE References: CVE-2021-21707,CVE-2021-21708,CVE-2022-31625,CVE-2022-31626,CVE-2022-31628,CVE-2022-31629,CVE-2022-31630,CVE-2022-37454
JIRA References: SLE-23639
Sources used:
openSUSE Leap 15.4 (src):    apache2-mod_php7-7.4.33-150400.4.13.1, php7-7.4.33-150400.4.13.1, php7-embed-7.4.33-150400.4.13.1, php7-fastcgi-7.4.33-150400.4.13.1, php7-fpm-7.4.33-150400.4.13.1, php7-test-7.4.33-150400.4.13.2
SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP4 (src):    php7-embed-7.4.33-150400.4.13.1
SUSE Linux Enterprise Module for Legacy Software 15-SP4 (src):    apache2-mod_php7-7.4.33-150400.4.13.1, php7-7.4.33-150400.4.13.1, php7-fastcgi-7.4.33-150400.4.13.1, php7-fpm-7.4.33-150400.4.13.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 15 Swamp Workflow Management 2022-11-18 14:25:57 UTC
SUSE-SU-2022:4068-1: An update that fixes 18 vulnerabilities, contains one feature is now available.

Category: security (important)
Bug References: 1203867,1203870,1204577,1204979
CVE References: CVE-2017-8923,CVE-2020-7068,CVE-2020-7069,CVE-2020-7070,CVE-2020-7071,CVE-2021-21702,CVE-2021-21703,CVE-2021-21704,CVE-2021-21705,CVE-2021-21706,CVE-2021-21707,CVE-2021-21708,CVE-2022-31625,CVE-2022-31626,CVE-2022-31628,CVE-2022-31629,CVE-2022-31630,CVE-2022-37454
JIRA References: SLE-23639
Sources used:
SUSE Linux Enterprise Software Development Kit 12-SP5 (src):    php74-7.4.33-1.47.2
SUSE Linux Enterprise Module for Web Scripting 12 (src):    php74-7.4.33-1.47.2

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 16 Swamp Workflow Management 2022-11-18 14:28:00 UTC
SUSE-SU-2022:4069-1: An update that fixes 18 vulnerabilities, contains one feature is now available.

Category: security (important)
Bug References: 1203867,1203870,1204577,1204979
CVE References: CVE-2017-8923,CVE-2020-7068,CVE-2020-7069,CVE-2020-7070,CVE-2020-7071,CVE-2021-21702,CVE-2021-21703,CVE-2021-21704,CVE-2021-21705,CVE-2021-21706,CVE-2021-21707,CVE-2021-21708,CVE-2022-31625,CVE-2022-31626,CVE-2022-31628,CVE-2022-31629,CVE-2022-31630,CVE-2022-37454
JIRA References: SLE-23639
Sources used:
openSUSE Leap 15.4 (src):    php7-7.4.33-150200.3.46.2
openSUSE Leap 15.3 (src):    php7-7.4.33-150200.3.46.2, php7-test-7.4.33-150200.3.46.2
SUSE Manager Server 4.1 (src):    php7-7.4.33-150200.3.46.2
SUSE Manager Retail Branch Server 4.1 (src):    php7-7.4.33-150200.3.46.2
SUSE Manager Proxy 4.1 (src):    php7-7.4.33-150200.3.46.2
SUSE Linux Enterprise Server for SAP 15-SP2 (src):    php7-7.4.33-150200.3.46.2
SUSE Linux Enterprise Server 15-SP2-LTSS (src):    php7-7.4.33-150200.3.46.2
SUSE Linux Enterprise Server 15-SP2-BCL (src):    php7-7.4.33-150200.3.46.2
SUSE Linux Enterprise Module for Web Scripting 15-SP3 (src):    php7-7.4.33-150200.3.46.2
SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP3 (src):    php7-7.4.33-150200.3.46.2
SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS (src):    php7-7.4.33-150200.3.46.2
SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS (src):    php7-7.4.33-150200.3.46.2
SUSE Enterprise Storage 7 (src):    php7-7.4.33-150200.3.46.2

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.