FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2013-6420

This CVE name corresponds to:

Entered Topic
2013-12-14 PHP5 -- memory corruption in openssl_x509_parse()

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2013-6420
Phase Assigned(20131104)

Description

The asn1_time_to_time_t function in ext/openssl/openssl.c in PHP before 5.3.28, 5.4.x before 5.4.23, and 5.5.x before 5.5.7 does not properly parse (1) notBefore and (2) notAfter timestamps in X.509 certificates, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted certificate that is not properly handled by the openssl_x509_parse function.

References

Source Reference
MISC https://www.sektioneins.de/advisories/advisory-012013-php-openssl_x509_parse-memory-corruption-vulnerability.html
CONFIRM http://git.php.net/?p=php-src.git;a=commit;h=c1224573c773b6845e83505f717fbf820fc18415
CONFIRM http://www.php.net/ChangeLog-5.php
CONFIRM https://bugzilla.redhat.com/show_bug.cgi?id=1036830
CONFIRM http://support.apple.com/kb/HT6150
CONFIRM http://forums.interworx.com/threads/8000-InterWorx-Version-5-0-14-Released-on-Beta-Channel!
HP HPSBMU03112
HP SSRT101447
SUSE openSUSE-SU-2013:1963
SUSE openSUSE-SU-2013:1964
SECTRACK 1029472
SECUNIA 59652