Asymmetric denial of service In phpseclib
Description
phpseclib guardrails needed on OID length
Impact
Any application using that loads untrusted ASN1 files (eg. X509 certificates, RSA PKCS8 private or public keys, etc).
Patches
https://github.com/phpseclib/phpseclib/commit/e32531001b4d62c66c3d824ccef54ffad835eb59
Workarounds
No.
Resources
https://github.com/phpseclib/phpseclib/commit/e32531001b4d62c66c3d824ccef54ffad835eb59 https://www.usenix.org/system/files/conference/usenixsecurity25/sec25cycle1-prepub-599-shi-bing.pdf
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 13 | 1.0.23-1 | ||
debian 13 | 2.0.47-1 | ||
packagist | 2.0.47, 3.0.36, 1.0.23 | ||
debian 11 | 2.0.30-2+deb11u2 | ||
debian 12 | 2.0.42-1+deb12u2 | ||
debian 12 | 3.0.19-1+deb12u3 | ||
debian 13 | 3.0.36-1 | ||
debian 11 | 1.0.19-3+deb11u2 | ||
debian 12 | 1.0.20-1+deb12u2 | ||
debian 14 | 3.0.36-1 |
1-10 of 11
10
Aliases
1. 2. 3. 4. 5. 6. 7. 8. 9.
References
1. 2. 3. 4. 5.