Описание
phpseclib is a PHP secure communications library. Prior to 1.0.29, 2.0.54, and 3.0.52, anyone loading untrusted ASN1 files (eg. X509 certificates, RSA PKCS8 private or public keys, etc). This is a bypass of CVE-2024-27355. This vulnerability is fixed in 1.0.29, 2.0.54, and 3.0.52.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| phpseclib | fixed | 1.0.29-1 | package | |
| phpseclib | fixed | 1.0.23-6+deb13u3 | trixie | package |
| phpseclib | fixed | 1.0.20-1+deb12u5 | bookworm | package |
| php-phpseclib | fixed | 2.0.54-1 | package | |
| php-phpseclib | fixed | 2.0.48-3+deb13u3 | trixie | package |
| php-phpseclib | fixed | 2.0.42-1+deb12u5 | bookworm | package |
| php-phpseclib3 | fixed | 3.0.52-1 | package | |
| php-phpseclib3 | fixed | 3.0.43-2+deb13u3 | trixie | package |
| php-phpseclib3 | fixed | 3.0.19-1+deb12u6 | bookworm | package |
Примечания
https://github.com/phpseclib/phpseclib/security/advisories/GHSA-3qpq-r242-jqj7
Fixed by: https://github.com/phpseclib/phpseclib/commit/d53d2021bcb9f6a04d5d44ec99e6bbef219a71bc (3.0.52, 2.0.54, 1.0.29)
EPSS
Связанные уязвимости
phpseclib is a PHP secure communications library. Prior to 1.0.29, 2.0.54, and 3.0.52, anyone loading untrusted ASN1 files (eg. X509 certificates, RSA PKCS8 private or public keys, etc). This is a bypass of CVE-2024-27355. This vulnerability is fixed in 1.0.29, 2.0.54, and 3.0.52.
phpseclib is a PHP secure communications library. Prior to 1.0.29, 2.0.54, and 3.0.52, anyone loading untrusted ASN1 files (eg. X509 certificates, RSA PKCS8 private or public keys, etc). This is a bypass of CVE-2024-27355. This vulnerability is fixed in 1.0.29, 2.0.54, and 3.0.52.
phpseclib has a CVE-2024-27355 mitigation bypass — OID amplification DoS in ASN1::decodeOID()
EPSS