ΠΠΏΠΈΡΠ°Π½ΠΈΠ΅
In phpseclib before 1.0.22, 2.x before 2.0.46, and 3.x before 3.0.33, some characters in Subject Alternative Name fields in TLS certificates are incorrectly allowed to have a special meaning in regular expressions (such as a + wildcard), leading to name confusion in X.509 certificate host verification.
ΠΠ°ΠΊΠ΅ΡΡ
| ΠΠ°ΠΊΠ΅Ρ | Π‘ΡΠ°ΡΡΡ | ΠΠ΅ΡΡΠΈΡ ΠΈΡΠΏΡΠ°Π²Π»Π΅Π½ΠΈΡ | Π Π΅Π»ΠΈΠ· | Π’ΠΈΠΏ |
|---|---|---|---|---|
| phpseclib | fixed | 1.0.22-1 | package | |
| phpseclib | fixed | 1.0.20-1+deb12u3 | bookworm | package |
| php-phpseclib | fixed | 2.0.46-1 | package | |
| php-phpseclib | fixed | 2.0.42-1+deb12u3 | bookworm | package |
| php-phpseclib3 | fixed | 3.0.33-1 | package | |
| php-phpseclib3 | fixed | 3.0.19-1+deb12u4 | bookworm | package |
ΠΡΠΈΠΌΠ΅ΡΠ°Π½ΠΈΡ
https://github.com/phpseclib/phpseclib/commit/6cd6e8ceab9f2b55c8cd81d2192bf98cbeaf4627 (1.0.22, 2.0.46, 3.0.33)
https://github.com/phpseclib/phpseclib/issues/1943
EPSS
Π‘Π²ΡΠ·Π°Π½Π½ΡΠ΅ ΡΡΠ·Π²ΠΈΠΌΠΎΡΡΠΈ
In phpseclib before 1.0.22, 2.x before 2.0.46, and 3.x before 3.0.33, some characters in Subject Alternative Name fields in TLS certificates are incorrectly allowed to have a special meaning in regular expressions (such as a + wildcard), leading to name confusion in X.509 certificate host verification.
In phpseclib before 1.0.22, 2.x before 2.0.46, and 3.x before 3.0.33, some characters in Subject Alternative Name fields in TLS certificates are incorrectly allowed to have a special meaning in regular expressions (such as a + wildcard), leading to name confusion in X.509 certificate host verification.
Name confusion in x509 Subject Alternative Name fields
EPSS