Описание
An issue was discovered in phpseclib 1.x before 1.0.23, 2.x before 2.0.47, and 3.x before 3.0.36. When processing the ASN.1 object identifier of a certificate, a sub identifier may be provided that leads to a denial of service (CPU consumption for decodeOID).
Релиз | Статус | Примечание |
---|---|---|
bionic | ignored | end of standard support |
devel | not-affected | 2.0.47-1 |
esm-apps/bionic | not-affected | code not present |
esm-apps/focal | released | 2.0.23-2ubuntu0.1~esm2 |
esm-apps/jammy | released | 2.0.36-1ubuntu0.1~esm2 |
esm-apps/noble | not-affected | 2.0.47-1 |
esm-apps/xenial | not-affected | code not present |
focal | ignored | end of standard support, was needed |
jammy | needed | |
mantic | ignored | end of life, was needs-triage |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
bionic | DNE | |
devel | not-affected | 3.0.37-1 |
esm-apps/jammy | released | 3.0.13-1ubuntu0.1~esm1 |
esm-apps/noble | not-affected | |
esm-infra/focal | DNE | |
focal | DNE | |
jammy | needed | |
mantic | ignored | end of life, was needs-triage |
noble | not-affected | |
oracular | not-affected | 3.0.37-1 |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
bionic | ignored | end of standard support |
devel | not-affected | 1.0.23-1 |
esm-apps/bionic | not-affected | code not present |
esm-apps/focal | released | 1.0.18-2ubuntu0.1~esm1 |
esm-apps/jammy | released | 1.0.20-1ubuntu0.1~esm1 |
esm-apps/noble | not-affected | 1.0.23-1 |
esm-apps/xenial | not-affected | code not present |
focal | ignored | end of standard support, was needed |
jammy | needed | |
mantic | ignored | end of life, was needs-triage |
Показывать по
7.5 High
CVSS3
Связанные уязвимости
An issue was discovered in phpseclib 1.x before 1.0.23, 2.x before 2.0.47, and 3.x before 3.0.36. When processing the ASN.1 object identifier of a certificate, a sub identifier may be provided that leads to a denial of service (CPU consumption for decodeOID).
An issue was discovered in phpseclib 1.x before 1.0.23, 2.x before 2.0 ...
phpseclib does not properly limit the ASN1 OID length
Уязвимость библиотеки криптографических протоколов phpseclib, связанная с неправильной проверкой входных данных, позволяющая нарушителю вызвать отказ в обслуживании
7.5 High
CVSS3