VDB
BDU%3A2022-02631
BDU%3A2022-02631
PUBLISHED
CVSS 7.5 HIGH
Уязвимость функции asn1_time_to_time_t (ext/openssl/openssl.c) интерпретатора языка программирования PHP, позволяющая нарушителю выполнить произвольный код
Risk Scores
CVSS 2.0
7.5
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat Inc., Canonical Ltd., Novell Inc., Сообщество свободного программного обеспечения, PHP Group | Red Hat Enterprise Linux, Ubuntu, OpenSUSE Leap, Debian GNU/Linux, PHP |
Timeline
- Apr 27, 2022 CVE Published
- Mar 21, 2026 Distribution Patch
- Mar 21, 2026 Distribution Patch
References
- http://git.php.net/?p=php-src.git;a=commit;h=c1224573c773b6845e83505f717fbf820fc18415 url
- https://bugzilla.redhat.com/show_bug.cgi?id=1036830 url
- http://www.php.net/ChangeLog-5.php url
- https://www.sektioneins.de/advisories/advisory-012013-php-openssl_x509_parse-memory-corruption-vulnerability.html url
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00125.html url
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00126.html url
- http://www.securitytracker.com/id/1029472 url
- http://support.apple.com/kb/HT6150 url
- http://secunia.com/advisories/59652 url
- https://h20564.www2.hp.com/hpsc/doc/public/display?docId=emr_na-c04463322 url
- http://www.securityfocus.com/bid/64225 url
- http://www.ubuntu.com/usn/USN-2055-1 url
- http://www.debian.org/security/2013/dsa-2816 url
- http://rhn.redhat.com/errata/RHSA-2013-1826.html url
- http://rhn.redhat.com/errata/RHSA-2013-1825.html url
- http://rhn.redhat.com/errata/RHSA-2013-1824.html url
- http://rhn.redhat.com/errata/RHSA-2013-1815.html url
- http://rhn.redhat.com/errata/RHSA-2013-1813.html url
- http://forums.interworx.com/threads/8000-InterWorx-Version-5-0-14-Released-on-Beta-Channel! url
- https://www.suse.com/security/cve/CVE-2013-6420 advisory
…and 3 more