packetstorm_rss ([info]packetstorm_rss) rakstīja,
@ 2013-12-22 15:06:00

Previous Entry  Add to memories!  Tell a Friend!  Next Entry
Mandriva Linux Security Advisory 2013-298
Mandriva Linux Security Advisory 2013-298 - The asn1_time_to_time_t function in ext/openssl/openssl.c in PHP before 5.3.28, 5.4.x before 5.4.23, and 5.5.x before 5.5.7 does not properly parse notAfter timestamps in X.509 certificates, which allows remote attackers to execute arbitrary code or cause a denial of service via a crafted certificate that is not properly handled by the openssl_x509_parse function. The updated packages have been upgraded to the 5.3.28 version which is not vulnerable to this issue. Additionally, some packages which requires so has been rebuilt for php-5.3.28.


Neesi iežurnalējies. Iežurnalēties?