Asymmetric denial of service In phpseclib/phpseclib
Description
Phpseclib needs guardrails on large binaryfield integers
Impact
Anyone loading untrusted ASN1 files (eg. X509 certificates, RSA PKCS8 private or public keys, etc)
Patches
https://github.com/phpseclib/phpseclib/commit/964d78101a70305df33f442f5490f0adb3b7e77f
Workarounds
No.
References
https://github.com/phpseclib/phpseclib/commit/964d78101a70305df33f442f5490f0adb3b7e77f https://www.usenix.org/system/files/usenixsecurity25-shi-bing.pdf
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
packagist | 3.0.34 | ||
debian 12 | 3.0.19-1+deb12u1 | ||
debian 13 | 3.0.34-1 | ||
debian 14 | 3.0.34-1 |
Aliases
1. 2. 3. 4. 5. 6. 7.
References
1. 2. 3. 4.