PT-2013-1335 · Openssl+5 · Openssl+5

Published

2013-08-18

·

Updated

2024-06-15

·

CVE-2013-4248

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions PHP versions prior to 5.4.18 PHP versions 5.5.x prior to 5.5.2
Description The issue arises from the improper handling of a '0' character in a domain name within the Subject Alternative Name field of an X.509 certificate by the openssl x509 parse function. This allows for man-in-the-middle attacks, where an attacker can spoof arbitrary SSL servers using a crafted certificate issued by a legitimate Certification Authority.
Recommendations For PHP versions prior to 5.4.18, update to version 5.4.18 or later. For PHP versions 5.5.x prior to 5.5.2, update to version 5.5.2 or later.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-02632
CESA-2013_1615
CVE-2013-4248
DSA-2742-1
HPSBUX03150
MGASA-2013-0264
OPENSUSE-SU-2024:10290-1
OPENSUSE-SU-2024:10344-1
OPENSUSE-SU-2024:11169-1
RHSA-2013:1307
RHSA-2013:1615
RHSA-2013_1307
RHSA-2013_1615
SUSE-SU-2014_0062-1
SUSE-SU-2014_0063-1
SUSE-SU-2014_0064-1
SUSE-SU-2014_0873-1
SUSE-SU-2014_0873-2

Affected Products

Centos
Hp-Ux
Openssl
Php
Red Hat
Suse