First published: Mon Dec 02 2013(Updated: )
Stefan Esser reported a vulnerability in the PHP openssl extension. A memory corruption flaw was found in the way the openssl_x509_parse() function of the PHP openssl extension parsed X.509 certificates. A remote attacker could use this flaw to provide a malicious self-signed certificate or a certificate signed by a trusted authority to a PHP application using the aforementioned function, causing the application to crash or, possibly, allow the attacker to execute arbitrary code with the privileges of the user running the PHP interpreter. Acknowledgements: Red Hat would like to thank the PHP project for reporting this issue. Upstream acknowledges Stefan Esser as the original reporter of this issue.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/php | <5.5.7 | 5.5.7 |
redhat/php | <5.4.23 | 5.4.23 |
redhat/php | <5.3.28 | 5.3.28 |
PHP PHP | =5.4.0 | |
PHP PHP | =5.4.1 | |
PHP PHP | =5.4.2 | |
PHP PHP | =5.4.3 | |
PHP PHP | =5.4.4 | |
PHP PHP | =5.4.5 | |
PHP PHP | =5.4.6 | |
PHP PHP | =5.4.7 | |
PHP PHP | =5.4.8 | |
PHP PHP | =5.4.9 | |
PHP PHP | =5.4.10 | |
PHP PHP | =5.4.11 | |
PHP PHP | =5.4.12 | |
PHP PHP | =5.4.12-rc1 | |
PHP PHP | =5.4.12-rc2 | |
PHP PHP | =5.4.13 | |
PHP PHP | =5.4.13-rc1 | |
PHP PHP | =5.4.14 | |
PHP PHP | =5.4.14-rc1 | |
PHP PHP | =5.4.15 | |
PHP PHP | =5.4.15-rc1 | |
PHP PHP | =5.4.16 | |
PHP PHP | =5.4.16-rc1 | |
PHP PHP | =5.4.17 | |
PHP PHP | =5.4.18 | |
PHP PHP | =5.4.19 | |
PHP PHP | =5.4.20 | |
PHP PHP | =5.4.21 | |
PHP PHP | =5.4.22 | |
openSUSE openSUSE | =11.4 | |
openSUSE openSUSE | =12.2 | |
openSUSE openSUSE | =12.3 | |
openSUSE openSUSE | =13.1 | |
Apple Mac OS X | <=10.9.1 | |
PHP PHP | <=5.3.27 | |
PHP PHP | =5.3.0 | |
PHP PHP | =5.3.1 | |
PHP PHP | =5.3.2 | |
PHP PHP | =5.3.3 | |
PHP PHP | =5.3.4 | |
PHP PHP | =5.3.5 | |
PHP PHP | =5.3.6 | |
PHP PHP | =5.3.7 | |
PHP PHP | =5.3.8 | |
PHP PHP | =5.3.9 | |
PHP PHP | =5.3.10 | |
PHP PHP | =5.3.11 | |
PHP PHP | =5.3.12 | |
PHP PHP | =5.3.13 | |
PHP PHP | =5.3.14 | |
PHP PHP | =5.3.15 | |
PHP PHP | =5.3.16 | |
PHP PHP | =5.3.17 | |
PHP PHP | =5.3.18 | |
PHP PHP | =5.3.19 | |
PHP PHP | =5.3.20 | |
PHP PHP | =5.3.21 | |
PHP PHP | =5.3.22 | |
PHP PHP | =5.3.23 | |
PHP PHP | =5.3.24 | |
PHP PHP | =5.3.25 | |
PHP PHP | =5.3.26 | |
PHP PHP | =5.5.0 | |
PHP PHP | =5.5.0-alpha1 | |
PHP PHP | =5.5.0-alpha2 | |
PHP PHP | =5.5.0-alpha3 | |
PHP PHP | =5.5.0-alpha4 | |
PHP PHP | =5.5.0-alpha5 | |
PHP PHP | =5.5.0-alpha6 | |
PHP PHP | =5.5.0-beta1 | |
PHP PHP | =5.5.0-beta2 | |
PHP PHP | =5.5.0-beta3 | |
PHP PHP | =5.5.0-beta4 | |
PHP PHP | =5.5.0-rc1 | |
PHP PHP | =5.5.0-rc2 | |
PHP PHP | =5.5.1 | |
PHP PHP | =5.5.2 | |
PHP PHP | =5.5.3 | |
PHP PHP | =5.5.4 | |
PHP PHP | =5.5.5 | |
PHP PHP | =5.5.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.