In phpseclib before 1.0.22, 2.x before 2.0.46, and 3.x before 3.0.33, some characters in Subject Alternative Name fields in TLS certificates are incorrectly allowed to have a special meaning in regular expressions (such as a + wildcard), leading to name confusion in X.509 certificate host verification.
Metrics
Affected Vendors & Products
References
History
Wed, 21 Aug 2024 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-436 | |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2024-06-27T00:00:00
Updated: 2024-08-21T20:02:23.834Z
Reserved: 2024-06-27T00:00:00
Link: CVE-2023-52892
Vulnrichment
Updated: 2024-08-02T23:18:41.296Z
NVD
Status : Awaiting Analysis
Published: 2024-06-27T22:15:10.277
Modified: 2024-08-21T20:35:00.760
Link: CVE-2023-52892
Redhat
No data.