PT-2009-5604 · Php+2 · Php+2

Publicado

2009-09-22

·

Atualizado

2018-10-30

·

CVE-2009-3291

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PHP versions prior to 5.2.11
Description The issue is related to the php openssl apply verification policy function in PHP, which does not properly perform certificate validation. This has an unknown impact and attack vectors, and is probably related to the ability to spoof certificates.
Recommendations For versions prior to 5.2.11, update to version 5.2.11 or later to resolve the issue.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-3291
DSA-1940-1
HPSBUX02543
RHSA-2010:0040
RHSA-2010_0040

Produtos afetados

Hp-Ux
Php
Red Hat