[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-2742-1 php5 -- interpretation conflict

ID: oval:org.secpod.oval:def:601090Date: (C)2013-09-25   (M)2024-02-19
Class: PATCHFamily: unix




It was discovered that PHP, a general-purpose scripting language commonly used for web application development, did not properly process embedded NUL characters in the subjectAltName extension of X.509 certificates. Depending on the application and with insufficient CA-level checks, this could be abused for impersonating other users.

Platform:
Debian 7.0
Debian 6.0
Product:
php5
Reference:
DSA-2742-1
CVE-2013-4248
CVE    1
CVE-2013-4248
CPE    93
cpe:/a:php:php:5.0.0:rc3
cpe:/a:php:php:5.3.10
cpe:/a:php:php:5.0.0:rc2
cpe:/a:php:php:5.0.0:rc1
...

© SecPod Technologies