Lack of data validation In phpseclib/phpseclib
Description
Name confusion in x509 Subject Alternative Name fields In phpseclib before 1.0.22, 2.x before 2.0.46, and 3.x before 3.0.33, some characters in Subject Alternative Name fields in TLS certificates are incorrectly allowed to have a special meaning in regular expressions (such as a + wildcard), leading to name confusion in X.509 certificate host verification.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
packagist | 1.0.22, 2.0.46, 3.0.33 | ||
debian 11 | - | ||
debian 12 | 2.0.42-1+deb12u3 | ||
debian 13 | 2.0.46-1 | ||
debian 12 | 3.0.19-1+deb12u4 | ||
debian 13 | 3.0.33-1 | ||
debian 11 | 1.0.19-3+deb11u3 | ||
debian 12 | 1.0.20-1+deb12u3 | ||
debian 13 | 1.0.22-1 | ||
debian 14 | 3.0.33-1 |
1-10 of 11
10
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3. 4.