Описание
phpseclib vulnerable to denial of service
In Math/BinaryField.php in phpseclib 3 before 3.0.34, excessively large degrees in binary fields can lead to a denial of service.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2023-49316
- https://github.com/phpseclib/phpseclib/commit/964d78101a70305df33f442f5490f0adb3b7e77f
- https://github.com/FriendsOfPHP/security-advisories/blob/master/phpseclib/phpseclib/CVE-2023-49316.yaml
- https://github.com/advisories/GHSA-jpr7-q523-hx25
- https://github.com/phpseclib/phpseclib/releases/tag/3.0.34
Пакеты
Наименование
phpseclib/phpseclib
composer
Затронутые версииВерсия исправления
>= 3.0.0, < 3.0.34
3.0.34
Связанные уязвимости
CVSS3: 7.5
ubuntu
около 2 лет назад
In Math/BinaryField.php in phpseclib 3 before 3.0.34, excessively large degrees can lead to a denial of service.
CVSS3: 7.5
nvd
около 2 лет назад
In Math/BinaryField.php in phpseclib 3 before 3.0.34, excessively large degrees can lead to a denial of service.
CVSS3: 7.5
debian
около 2 лет назад
In Math/BinaryField.php in phpseclib 3 before 3.0.34, excessively larg ...