CVE-2023-27560: High severity phpseclib vulnerability
Infinite Loop vulnerability
Other sources
Math/PrimeField.php in phpseclib 3.x before 3.0.19 has an infinite loop with composite primefields.
Math/PrimeField.php in phpseclib has an infinite loop with composite primefields. This vulnerability was introduced in version 3.0.0, and has been patched in 3.0.19. The CVE for this issue originally identified the the vulnerable version as 2.x, however, the vulnerable functionality was not introduced until version 3.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-27560?
CVE-2023-27560 is an Infinite Loop vulnerability in phpseclib.
What is the severity of CVE-2023-27560?
CVE-2023-27560 has a severity rating of 7.5 (High).
How does CVE-2023-27560 affect phpseclib?
CVE-2023-27560 affects phpseclib versions 3.0.0 to 3.0.19.
How can I fix CVE-2023-27560?
To fix CVE-2023-27560, update phpseclib to version 3.0.19 or later.
Where can I find more information about CVE-2023-27560?
You can find more information about CVE-2023-27560 in the following references: [link1](https://github.com/advisories/GHSA-hm7p-r324-hhf3), [link2](https://nvd.nist.gov/vuln/detail/CVE-2023-27560), [link3](https://github.com/phpseclib/phpseclib/commit/6298d1cd55c3ffa44533bd41906caec246b60440).