Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hm7p-r324-hhf3

Опубликовано: 03 мар. 2023
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

phpseclib Infinite Loop vulnerability

Math/PrimeField.php in phpseclib has an infinite loop with composite primefields. This vulnerability was introduced in version 3.0.0, and has been patched in 3.0.19. The CVE for this issue originally identified the the vulnerable version as 2.x, however, the vulnerable functionality was not introduced until version 3.

Пакеты

Наименование

phpseclib/phpseclib

composer
Затронутые версииВерсия исправления

>= 3.0.0, < 3.0.19

3.0.19

EPSS

Процентиль: 47%
0.0024
Низкий

7.5 High

CVSS3

Дефекты

CWE-835

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 3 года назад

Math/PrimeField.php in phpseclib 3.x before 3.0.19 has an infinite loop with composite primefields.

CVSS3: 7.5
nvd
почти 3 года назад

Math/PrimeField.php in phpseclib 3.x before 3.0.19 has an infinite loop with composite primefields.

CVSS3: 7.5
debian
почти 3 года назад

Math/PrimeField.php in phpseclib 3.x before 3.0.19 has an infinite loo ...

EPSS

Процентиль: 47%
0.0024
Низкий

7.5 High

CVSS3

Дефекты

CWE-835