Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
php-exploit_cve-2022-31630 — Proof-of-concept exploit for CVE-2022-31630, an out-of-bounds read vulnerability in PHP's GD extension. Demonstrates crash and memory disclosure in affected PHP versions. Includes Docker-based lab for safe testing. | Kitploit
Tools/GitHubGitHub/sepkascurty-cpu/php-exploit_cve-2022-31630
Vulnerability AnalysisExploitationLearning & EducationBinary ExploitationLabs & Practice
GitHubsepkascurty-cpu/php-exploit_cve-2022-31630

php-exploit_cve-2022-31630

Proof-of-concept exploit for CVE-2022-31630, an out-of-bounds read vulnerability in PHP's GD extension. Demonstrates crash and memory disclosure in affected PHP versions. Includes Docker-based lab for safe testing.

View Repository
1126 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

#CVE-2022-31630 – Proof of Concept Exploit

Warning: This code is made only for educational purposes and testing in an isolated laboratory environment. Use on other systems without permission is illegal and irresponsible.


📌 Description

CVE-2022-31630 is an Out-of-Bounds (OOB) Read vulnerability in the GD PHP extension, specifically in the imageloadfont() function. This vulnerability allows an attacker who can control the font file loaded by a PHP application to read data beyond the allocated buffer. Possible impacts include:

· Denial of Service (crash) – application stops responding. · Information Disclosure – sensitive data from memory can be read (e.g., keys, tokens, or other data fragments).

Affected PHP Versions

· PHP 7.4.x before 7.4.33 · PHP 8.0.x before 8.0.25 · PHP 8.1.x before 8.1.12

PHP 7.4.33 is the first version to receive a patch for this CVE. This repository provides a Proof of Concept (PoC) to demonstrate the behavioral difference between vulnerable versions (≤ 7.4.32) and patched versions (≥ 7.4.33).


🔍 Technical Details

The vulnerability stems from insufficient input validation when reading GD font files (.gdf format). The font file has the following header structure:

Byte offset Size (bytes) Description 0 2 Magic number (0x01BE) 2 2 Number of characters (nchars) 4 2 Character width (width) (in pixels) 6 2 Character height (height) 8 2 Number of bytes per character (char_offset)

If the width value is set very large (e.g., 65535), the buffer size calculation for storing character bitmaps becomes incorrect. As a result, the allocated buffer is too small. When the imagechar() function subsequently reads a character from that font, it accesses memory beyond the buffer boundary – this is the Out-of-Bounds Read.


🧪 Test Requirements

· Docker (to run isolated environment) · PHP version 7.4.32 or 7.4.33 (can use Docker images php:7.4.32-cli / php:7.4.33-cli) · GD extension (will be installed inside the container)


🚀 How to Use the PoC

  1. Clone this repository
git clone https://github.com/sepkascurty-cpu/php-exploit_cve-2022-31630.git
cd exploit_cve-2022-31630
  1. Run a container with the desired PHP version

To test the vulnerable version (7.4.32):

docker run -it --rm -v $(pwd):/app php:7.4.32-cli bash

To test the patched version (7.4.33):

docker run -it --rm -v $(pwd):/app php:7.4.33-cli bash
  1. Inside the container, install the GD extension
cd /app
apt-get update
apt-get install -y libfreetype6-dev libjpeg62-turbo-dev libpng-dev
docker-php-ext-configure gd --with-freetype --with-jpeg
docker-php-ext-install gd
  1. Run the exploit
php exploit_cve-2022-31630.php

📊 Example Output

PHP Version Expected Result 7.4.32 (vulnerable) Program crashes with Segmentation Fault or memory leak occurs (dummy data from memory visible). 7.4.33 (patched) Execution completes normally, output.png image file saved, no crash.


🛡️ Mitigation

· Update PHP to the latest version containing the patch: · PHP 7.4.33 or later · PHP 8.0.25 or later · PHP 8.1.12 or later · If unable to update immediately, disable the GD extension or the imageloadfont() function if not strictly necessary. · Apply the principle of least privilege to the application to minimize impact in case of memory leak.


📚 References

· CVE-2022-31630 on NVD · Patch commit in php-src · PHP Release Announcements


⚠️ Disclaimer

This repository is provided for educational and security research purposes. The author is not responsible for any misuse of this code. Ensure you only test in environments you own or have written permission.


Made for the Indonesian cybersecurity community.

Download Tool