Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2012-6113

Опубликовано: 19 янв. 2013
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5

Описание

The openssl_encrypt function in ext/openssl/openssl.c in PHP 5.3.9 through 5.3.13 does not initialize a certain variable, which allows remote attackers to obtain sensitive information from process memory by providing zero bytes of input data.

РелизСтатусПримечание
devel

not-affected

5.4.9-4ubuntu1
hardy

not-affected

5.2.4-2ubuntu5.26
lucid

not-affected

5.3.2-1ubuntu4.18
oneiric

not-affected

5.3.6-13ubuntu3.9
precise

released

5.3.10-1ubuntu3.5
quantal

not-affected

5.4.6-1ubuntu1.1
upstream

released

5.3.14

Показывать по

EPSS

Процентиль: 59%
0.00379
Низкий

5 Medium

CVSS2

Связанные уязвимости

redhat
больше 13 лет назад

The openssl_encrypt function in ext/openssl/openssl.c in PHP 5.3.9 through 5.3.13 does not initialize a certain variable, which allows remote attackers to obtain sensitive information from process memory by providing zero bytes of input data.

nvd
больше 12 лет назад

The openssl_encrypt function in ext/openssl/openssl.c in PHP 5.3.9 through 5.3.13 does not initialize a certain variable, which allows remote attackers to obtain sensitive information from process memory by providing zero bytes of input data.

debian
больше 12 лет назад

The openssl_encrypt function in ext/openssl/openssl.c in PHP 5.3.9 thr ...

github
больше 3 лет назад

The openssl_encrypt function in ext/openssl/openssl.c in PHP 5.3.9 through 5.3.13 does not initialize a certain variable, which allows remote attackers to obtain sensitive information from process memory by providing zero bytes of input data.

EPSS

Процентиль: 59%
0.00379
Низкий

5 Medium

CVSS2