CVE-2013-6420

The asn1_time_to_time_t function in ext/openssl/openssl.c in PHP before 5.3.28, 5.4.x before 5.4.23, and 5.5.x before 5.5.7 does not properly parse (1) notBefore and (2) notAfter timestamps in X.509 certificates, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted certificate that is not properly handled by the openssl_x509_parse function.
References
Link Resource
http://forums.interworx.com/threads/8000-InterWorx-Version-5-0-14-Released-on-Beta-Channel%21
http://git.php.net/?p=php-src.git%3Ba=commit%3Bh=c1224573c773b6845e83505f717fbf820fc18415
http://lists.opensuse.org/opensuse-updates/2013-12/msg00125.html
http://lists.opensuse.org/opensuse-updates/2013-12/msg00126.html
http://rhn.redhat.com/errata/RHSA-2013-1813.html
http://rhn.redhat.com/errata/RHSA-2013-1815.html
http://rhn.redhat.com/errata/RHSA-2013-1824.html
http://rhn.redhat.com/errata/RHSA-2013-1825.html
http://rhn.redhat.com/errata/RHSA-2013-1826.html
http://secunia.com/advisories/59652
http://support.apple.com/kb/HT6150
http://www.debian.org/security/2013/dsa-2816
http://www.php.net/ChangeLog-5.php
http://www.securityfocus.com/bid/64225
http://www.securitytracker.com/id/1029472
http://www.ubuntu.com/usn/USN-2055-1
https://bugzilla.redhat.com/show_bug.cgi?id=1036830 Patch
https://h20564.www2.hp.com/hpsc/doc/public/display?docId=emr_na-c04463322
https://h20564.www2.hp.com/hpsc/doc/public/display?docId=emr_na-c04463322
https://www.sektioneins.de/advisories/advisory-012013-php-openssl_x509_parse-memory-corruption-vulnerability.html Exploit
http://forums.interworx.com/threads/8000-InterWorx-Version-5-0-14-Released-on-Beta-Channel%21
http://git.php.net/?p=php-src.git%3Ba=commit%3Bh=c1224573c773b6845e83505f717fbf820fc18415
http://lists.opensuse.org/opensuse-updates/2013-12/msg00125.html
http://lists.opensuse.org/opensuse-updates/2013-12/msg00126.html
http://rhn.redhat.com/errata/RHSA-2013-1813.html
http://rhn.redhat.com/errata/RHSA-2013-1815.html
http://rhn.redhat.com/errata/RHSA-2013-1824.html
http://rhn.redhat.com/errata/RHSA-2013-1825.html
http://rhn.redhat.com/errata/RHSA-2013-1826.html
http://secunia.com/advisories/59652
http://support.apple.com/kb/HT6150
http://www.debian.org/security/2013/dsa-2816
http://www.php.net/ChangeLog-5.php
http://www.securityfocus.com/bid/64225
http://www.securitytracker.com/id/1029472
http://www.ubuntu.com/usn/USN-2055-1
https://bugzilla.redhat.com/show_bug.cgi?id=1036830 Patch
https://h20564.www2.hp.com/hpsc/doc/public/display?docId=emr_na-c04463322
https://h20564.www2.hp.com/hpsc/doc/public/display?docId=emr_na-c04463322
https://www.sektioneins.de/advisories/advisory-012013-php-openssl_x509_parse-memory-corruption-vulnerability.html Exploit
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:php:php:5.4.0:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.4.1:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.4.2:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.4.3:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.4.4:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.4.5:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.4.6:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.4.7:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.4.8:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.4.9:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.4.10:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.4.11:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.4.12:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.4.12:rc1:*:*:*:*:*:*
cpe:2.3:a:php:php:5.4.12:rc2:*:*:*:*:*:*
cpe:2.3:a:php:php:5.4.13:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.4.13:rc1:*:*:*:*:*:*
cpe:2.3:a:php:php:5.4.14:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.4.14:rc1:*:*:*:*:*:*
cpe:2.3:a:php:php:5.4.15:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.4.15:rc1:*:*:*:*:*:*
cpe:2.3:a:php:php:5.4.16:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.4.16:rc1:*:*:*:*:*:*
cpe:2.3:a:php:php:5.4.17:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.4.18:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.4.19:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.4.20:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.4.21:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.4.22:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:opensuse:opensuse:11.4:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:12.2:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:12.3:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*

Configuration 4 (hide)

OR cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.3.0:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.3.1:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.3.2:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.3.3:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.3.4:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.3.5:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.3.6:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.3.7:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.3.8:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.3.9:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.3.10:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.3.11:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.3.12:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.3.13:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.3.14:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.3.15:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.3.16:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.3.17:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.3.18:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.3.19:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.3.20:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.3.21:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.3.22:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.3.23:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.3.24:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.3.25:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.3.26:*:*:*:*:*:*:*

Configuration 5 (hide)

OR cpe:2.3:a:php:php:5.5.0:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.0:alpha1:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.0:alpha2:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.0:alpha3:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.0:alpha4:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.0:alpha5:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.0:alpha6:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.0:beta1:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.0:beta2:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.0:beta3:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.0:beta4:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.0:rc1:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.0:rc2:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.1:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.2:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.3:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.4:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.5:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.5.6:*:*:*:*:*:*:*

History

21 Nov 2024, 01:59

Type Values Removed Values Added
References () http://forums.interworx.com/threads/8000-InterWorx-Version-5-0-14-Released-on-Beta-Channel%21 - () http://forums.interworx.com/threads/8000-InterWorx-Version-5-0-14-Released-on-Beta-Channel%21 -
References () http://git.php.net/?p=php-src.git%3Ba=commit%3Bh=c1224573c773b6845e83505f717fbf820fc18415 - () http://git.php.net/?p=php-src.git%3Ba=commit%3Bh=c1224573c773b6845e83505f717fbf820fc18415 -
References () http://lists.opensuse.org/opensuse-updates/2013-12/msg00125.html - () http://lists.opensuse.org/opensuse-updates/2013-12/msg00125.html -
References () http://lists.opensuse.org/opensuse-updates/2013-12/msg00126.html - () http://lists.opensuse.org/opensuse-updates/2013-12/msg00126.html -
References () http://rhn.redhat.com/errata/RHSA-2013-1813.html - () http://rhn.redhat.com/errata/RHSA-2013-1813.html -
References () http://rhn.redhat.com/errata/RHSA-2013-1815.html - () http://rhn.redhat.com/errata/RHSA-2013-1815.html -
References () http://rhn.redhat.com/errata/RHSA-2013-1824.html - () http://rhn.redhat.com/errata/RHSA-2013-1824.html -
References () http://rhn.redhat.com/errata/RHSA-2013-1825.html - () http://rhn.redhat.com/errata/RHSA-2013-1825.html -
References () http://rhn.redhat.com/errata/RHSA-2013-1826.html - () http://rhn.redhat.com/errata/RHSA-2013-1826.html -
References () http://secunia.com/advisories/59652 - () http://secunia.com/advisories/59652 -
References () http://support.apple.com/kb/HT6150 - () http://support.apple.com/kb/HT6150 -
References () http://www.debian.org/security/2013/dsa-2816 - () http://www.debian.org/security/2013/dsa-2816 -
References () http://www.php.net/ChangeLog-5.php - () http://www.php.net/ChangeLog-5.php -
References () http://www.securityfocus.com/bid/64225 - () http://www.securityfocus.com/bid/64225 -
References () http://www.securitytracker.com/id/1029472 - () http://www.securitytracker.com/id/1029472 -
References () http://www.ubuntu.com/usn/USN-2055-1 - () http://www.ubuntu.com/usn/USN-2055-1 -
References () https://bugzilla.redhat.com/show_bug.cgi?id=1036830 - Patch () https://bugzilla.redhat.com/show_bug.cgi?id=1036830 - Patch
References () https://h20564.www2.hp.com/hpsc/doc/public/display?docId=emr_na-c04463322 - () https://h20564.www2.hp.com/hpsc/doc/public/display?docId=emr_na-c04463322 -
References () https://www.sektioneins.de/advisories/advisory-012013-php-openssl_x509_parse-memory-corruption-vulnerability.html - Exploit () https://www.sektioneins.de/advisories/advisory-012013-php-openssl_x509_parse-memory-corruption-vulnerability.html - Exploit

07 Nov 2023, 02:17

Type Values Removed Values Added
References
  • {'url': 'http://forums.interworx.com/threads/8000-InterWorx-Version-5-0-14-Released-on-Beta-Channel!', 'name': 'http://forums.interworx.com/threads/8000-InterWorx-Version-5-0-14-Released-on-Beta-Channel!', 'tags': [], 'refsource': 'CONFIRM'}
  • {'url': 'http://git.php.net/?p=php-src.git;a=commit;h=c1224573c773b6845e83505f717fbf820fc18415', 'name': 'http://git.php.net/?p=php-src.git;a=commit;h=c1224573c773b6845e83505f717fbf820fc18415', 'tags': ['Patch'], 'refsource': 'CONFIRM'}
  • () http://forums.interworx.com/threads/8000-InterWorx-Version-5-0-14-Released-on-Beta-Channel%21 -
  • () http://git.php.net/?p=php-src.git%3Ba=commit%3Bh=c1224573c773b6845e83505f717fbf820fc18415 -

Information

Published : 2013-12-17 04:46

Updated : 2024-11-21 01:59


NVD link : CVE-2013-6420

Mitre link : CVE-2013-6420

CVE.ORG link : CVE-2013-6420


JSON object : View

Products Affected

php

  • php

opensuse

  • opensuse

apple

  • mac_os_x
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer