Description
The asn1_time_to_time_t function in ext/openssl/openssl.c in PHP before 5.3.28, 5.4.x before 5.4.23, and 5.5.x before 5.5.7 does not properly parse (1) notBefore and (2) notAfter timestamps in X.509 certificates, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted certificate that is not properly handled by the openssl_x509_parse function.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-2816-1 | php5 security update |
Ubuntu USN |
USN-2055-1 | PHP vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T17:39:01.267Z
Reserved: 2013-11-04T00:00:00.000Z
Link: CVE-2013-6420
No data.
Status : Deferred
Published: 2013-12-17T04:46:45.877
Modified: 2025-04-11T00:51:21.963
Link: CVE-2013-6420
OpenCVE Enrichment
No data.
Debian DSA
Ubuntu USN