PT-2024-14775 · Phpseclib+4 · Phpseclib+4

CVE-2023-52892

·

Published

2024-06-27

·

Updated

2025-10-22

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions phpseclib versions 1.0.0 through 1.0.21 phpseclib versions 2.0.0 through 2.0.45 phpseclib versions 3.0.0 through 3.0.32
Description The issue arises from the incorrect handling of certain characters in Subject Alternative Name fields within TLS certificates, allowing them to have special meanings in regular expressions. This can lead to name confusion during X.509 certificate host verification, potentially affecting the security of the connection.
Recommendations For versions 1.0.0 through 1.0.21, update to version 1.0.22 or later. For versions 2.0.0 through 2.0.45, update to version 2.0.46 or later. For versions 3.0.0 through 3.0.32, update to version 3.0.33 or later.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-52892
GHSA-FF7Q-6VWH-V9M4
USN-7404-1

Affected Products

Debian
Linuxmint
Red Os
Ubuntu
Phpseclib