PT-2013-1334 · Openssl+4 · Openssl+4

Stefan Esser

·

Published

2013-12-11

·

Updated

2024-06-15

·

CVE-2013-6420

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PHP versions prior to 5.3.28 PHP versions 5.4.x prior to 5.4.23 PHP versions 5.5.x prior to 5.5.7
Description The issue arises from the improper parsing of notBefore and notAfter timestamps in X.509 certificates by the asn1 time to time t function. This can lead to memory corruption, allowing remote attackers to execute arbitrary code or cause a denial of service. The vulnerability is caused by a buffer overflow in the OpenSSL library used by PHP.
Recommendations For PHP versions prior to 5.3.28, update to version 5.3.28 or later. For PHP versions 5.4.x prior to 5.4.23, update to version 5.4.23 or later. For PHP versions 5.5.x prior to 5.5.7, update to version 5.5.7 or later.

Exploit

Fix

RCE

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-02631
CESA-2013_1813
CVE-2013-6420
DSA-2816-1
MGASA-2013-0379
OPENSUSE-SU-2024:10290-1
OPENSUSE-SU-2024:10344-1
OPENSUSE-SU-2024:11169-1
RHSA-2013:1813
RHSA-2013:1814
RHSA-2013:1815
RHSA-2013:1824
RHSA-2013:1825
RHSA-2013:1826
RHSA-2013_1813
RHSA-2013_1814

Affected Products

Centos
Openssl
Php
Red Hat
Suse