PT-2013-1334 · Openssl+4 · Openssl+4

Stefan Esser

·

Publicado

2013-12-11

·

Atualizado

2024-06-15

·

CVE-2013-6420

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PHP versions prior to 5.3.28 PHP versions 5.4.x prior to 5.4.23 PHP versions 5.5.x prior to 5.5.7
Description The issue arises from the improper parsing of notBefore and notAfter timestamps in X.509 certificates by the asn1 time to time t function. This can lead to memory corruption, allowing remote attackers to execute arbitrary code or cause a denial of service. The vulnerability is caused by a buffer overflow in the OpenSSL library used by PHP.
Recommendations For PHP versions prior to 5.3.28, update to version 5.3.28 or later. For PHP versions 5.4.x prior to 5.4.23, update to version 5.4.23 or later. For PHP versions 5.5.x prior to 5.5.7, update to version 5.5.7 or later.

Exploit

Correção

RCE

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2022-02631
CESA-2013_1813
CVE-2013-6420
DSA-2816-1
MGASA-2013-0379
OPENSUSE-SU-2024:10290-1
OPENSUSE-SU-2024:10344-1
OPENSUSE-SU-2024:11169-1
RHSA-2013:1813
RHSA-2013:1814
RHSA-2013:1815
RHSA-2013:1824
RHSA-2013:1825
RHSA-2013:1826
RHSA-2013_1813
RHSA-2013_1814

Produtos afetados

Centos
Openssl
Php
Red Hat
Suse