Description
The php_openssl_apply_verification_policy function in PHP before 5.2.11 does not properly perform certificate validation, which has unknown impact and attack vectors, probably related to an ability to spoof certificates.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-1940-1 | New php5 packages fix several issues |
EUVD |
EUVD-2009-3273 | The php_openssl_apply_verification_policy function in PHP before 5.2.11 does not properly perform certificate validation, which has unknown impact and attack vectors, probably related to an ability to spoof certificates. |
Ubuntu USN |
USN-862-1 | PHP vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T06:22:24.519Z
Reserved: 2009-09-22T00:00:00.000Z
Link: CVE-2009-3291
No data.
Status : Deferred
Published: 2009-09-22T10:30:00.750
Modified: 2025-04-09T00:30:58.490
Link: CVE-2009-3291
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD
Ubuntu USN