#VU67755 Infinite loop in PHP - CVE-2022-31628
Published: September 29, 2022 / Updated: October 27, 2023
PHP
PHP Group
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to infinite loop within the phar uncompressor code when processing "quines" gzip files. A remote attacker can pass a specially crafted archive to the application, consume all available system resources and cause denial of service conditions.