You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
An issue was discovered in phpseclib 1.x before 1.0.23, 2.x before 2.0.47, and 3.x before 3.0.36. An attacker can construct a malformed certificate containing an extremely large prime to cause a denial of service (CPU consumption for an isPrime primality check). NOTE: this issue was introduced when attempting to fix CVE-2023-27560.
An issue was discovered in phpseclib 1.x before 1.0.23, 2.x before 2.0.47, and 3.x before 3.0.36. When processing the ASN.1 object identifier of a certificate, a sub identifier may be provided that leads to a denial of service (CPU consumption for decodeOID).
mend-bolt-for-githubbot
changed the title
phpseclib/phpseclib-2.0.41: 1 vulnerabilities (highest severity is: 5.5)
phpseclib/phpseclib-2.0.41: 2 vulnerabilities (highest severity is: 7.5)
Mar 17, 2024
PHP Secure Communications Library - Pure-PHP implementations of RSA, AES, SSH2, SFTP, X.509 etc.
Library home page: https://api.github.com/repos/phpseclib/phpseclib/zipball/7e763c6f97ec1fcb37c46aa8ecfc20a2c71d9c1b
Found in HEAD commit: ad06856b39153f425da332dea44087d7b4bf93ce
Vulnerabilities
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
Vulnerable Library - phpseclib/phpseclib-2.0.41
PHP Secure Communications Library - Pure-PHP implementations of RSA, AES, SSH2, SFTP, X.509 etc.
Library home page: https://api.github.com/repos/phpseclib/phpseclib/zipball/7e763c6f97ec1fcb37c46aa8ecfc20a2c71d9c1b
Dependency Hierarchy:
Found in HEAD commit: ad06856b39153f425da332dea44087d7b4bf93ce
Found in base branch: raconteur
Vulnerability Details
An issue was discovered in phpseclib 1.x before 1.0.23, 2.x before 2.0.47, and 3.x before 3.0.36. An attacker can construct a malformed certificate containing an extremely large prime to cause a denial of service (CPU consumption for an isPrime primality check). NOTE: this issue was introduced when attempting to fix CVE-2023-27560.
Publish Date: 2024-03-01
URL: CVE-2024-27354
CVSS 3 Score Details (7.5)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: https://www.cve.org/CVERecord?id=CVE-2024-27354
Release Date: 2024-03-01
Fix Resolution: 1.0.23,2.0.47,3.0.36
Step up your Open Source Security Game with Mend here
Vulnerable Library - phpseclib/phpseclib-2.0.41
PHP Secure Communications Library - Pure-PHP implementations of RSA, AES, SSH2, SFTP, X.509 etc.
Library home page: https://api.github.com/repos/phpseclib/phpseclib/zipball/7e763c6f97ec1fcb37c46aa8ecfc20a2c71d9c1b
Dependency Hierarchy:
Found in HEAD commit: ad06856b39153f425da332dea44087d7b4bf93ce
Found in base branch: raconteur
Vulnerability Details
An issue was discovered in phpseclib 1.x before 1.0.23, 2.x before 2.0.47, and 3.x before 3.0.36. When processing the ASN.1 object identifier of a certificate, a sub identifier may be provided that leads to a denial of service (CPU consumption for decodeOID).
Publish Date: 2024-03-01
URL: CVE-2024-27355
CVSS 3 Score Details (6.5)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: https://www.cve.org/CVERecord?id=CVE-2024-27355
Release Date: 2024-03-01
Fix Resolution: 1.0.23,2.0.47,3.0.36
Step up your Open Source Security Game with Mend here
The text was updated successfully, but these errors were encountered: