PT-2024-14775 · Phpseclib+4 · Phpseclib+4

Published

2024-06-27

·

Updated

2025-10-22

·

CVE-2023-52892

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions phpseclib versions 1.0.0 through 1.0.21 phpseclib versions 2.0.0 through 2.0.45 phpseclib versions 3.0.0 through 3.0.32
Description The issue arises from the incorrect handling of certain characters in Subject Alternative Name fields within TLS certificates, allowing them to have special meanings in regular expressions. This can lead to name confusion during X.509 certificate host verification, potentially affecting the security of the connection.
Recommendations For versions 1.0.0 through 1.0.21, update to version 1.0.22 or later. For versions 2.0.0 through 2.0.45, update to version 2.0.46 or later. For versions 3.0.0 through 3.0.32, update to version 3.0.33 or later.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2023-52892
GHSA-FF7Q-6VWH-V9M4
USN-7404-1

Affected Products

Debian
Linuxmint
Red Os
Ubuntu
Phpseclib