oss-sec mailing list archives
CVE Request -- php - handling of certs with null bytes
From: Oden Eriksson <oeriksson () mandriva com>
Date: Wed, 14 Aug 2013 10:47:06 +0200
Hello, A similar flaw as in ruby and python was discovered and fixed for php. ruby - CVE-2013-4073 python - CVE-2013-4238 php - CVE-2013-???? http://www.ruby-lang.org/en/news/2013/06/27/hostname-check-bypassing-vulnerability-in-openssl-client-cve-2013-4073/[1] Upstream fixes: http://git.php.net/?p=php-src.git;a=commit;h=dcea4ec698dcae39b7bba6f6aa08933cbfee6755[2] http://git.php.net/?p=php-src.git;a=commit;h=2874696a5a8d46639d261571f915c493cd875897[3] _https://bugs.mageia.org/show_bug.cgi?id=10997_ Cheers. -------- [1] http://www.ruby-lang.org/en/news/2013/06/27/hostname-check-bypassing-vulnerability-in-openssl-client-cve-2013-4073/ [2] http://git.php.net/?p=php-src.git;a=commit;h=dcea4ec698dcae39b7bba6f6aa08933cbfee6755 [3] http://git.php.net/?p=php-src.git;a=commit;h=2874696a5a8d46639d261571f915c493cd875897
Current thread:
- CVE Request -- php - handling of certs with null bytes Oden Eriksson (Aug 14)
- Re: CVE Request -- php - handling of certs with null bytes Kurt Seifried (Aug 14)