[SECURITY] [DLA 4670-1] php-phpseclib security update
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
- -----------------------------------------------------------------------
Debian LTS Advisory DLA-4670-1 debian-lts@lists.debian.org
https://www.debian.org/lts/security/ Utkarsh Gupta
July 05, 2026 https://wiki.debian.org/LTS
- -----------------------------------------------------------------------
Package : php-phpseclib
Version : 2.0.30-2+deb11u3
CVE ID : CVE-2023-52892 CVE-2026-32935 CVE-2026-40194
CVE-2026-44167 CVE-2026-55599
Debian Bug : 1131483
Several vulnerabilities were discovered in phpseclib, a PHP secure
communications library, which could result in hostname validation
bypass, timing side-channel attacks, denial of service, and
server-side request forgery (SSRF).
CVE-2023-52892
X509.php did not properly escape regular expression special
characters in a certificate's subjectAltName, allowing a crafted
certificate to bypass hostname validation in validateURL().
CVE-2026-32935
The block cipher unpadding routine in Crypt/Base.php used a
short-circuiting comparison, creating a timing side channel that
could aid padding-oracle-style attacks.
CVE-2026-40194
The SSH2 implementation compared incoming packet HMACs using a
variable-time string comparison, creating a timing side channel
on cryptographic material.
CVE-2026-44167
The ASN.1 decoder's 4096-byte Object Identifier limit (mitigating
CVE-2024-27355) was still large enough to allow an "OID
amplification" denial of service via crafted ASN.1 structures.
CVE-2026-55599
File_X509 could automatically fetch a URL from a certificate's
Authority Information Access extension without validating the
destination, allowing SSRF via a crafted certificate.
For Debian 11 bullseye, these problems have been fixed in version
2.0.30-2+deb11u3.
We recommend that you upgrade your php-phpseclib packages.
For the detailed security status of php-phpseclib please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/php-phpseclib
Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCAAdFiEEbJ0QSEqa5Mw4X3xxgj6WdgbDS5YFAmpJX4sACgkQgj6WdgbD
S5aGmhAApDNuC1UmF+a+1SEZB16ugTc+/wo8nk+gP3n00aN2sG1FpB1k1yR5x1Y4
QW9SPgPftYcEFT9p1I1zGC0AOXHC091BfrOeKN2glgJuknqvY6qdG92qxA3jkwxh
3DinrIRO5Oq+EaKH7NdcYhOANXA6S3LCny3gio6I+qfPR7RBbxFYrM73VpAgYu1e
9D0T6Qx2ypHINEhz3NYOTGmmDsG1c6uSuQLrMF8Gx5BJwoeGgCv4GA5LmZDbgw5y
2O66wFMXJGAGvpuH1qB/eKXAUu/nocHi9yIAWeUcYMYDZdnChaHnM/VIX4lpXqWu
CmiNxS5/VlcZ/INteL7iujHXmPvnGz3nc3qwMy5rh8Pm4hAD5Dx5uMe176v5zFWC
4/CgvrWVWI1zTufwFNZAuA1cwXRAwBqXhYT1pgGxd/eHUHMmBEoSmUsQPJ3sJ6uW
nDiJq0zvWrDs9tQ+hKH5cmnHUM46VKUfNAdcZ+mnPE2X31chSQJ54wKGHV2VQBRY
ndZHL5T883ELCzxsF1ksJNjIUgidHDTTIOc0VRHbzNuFrxHeoGxGO5eF0Bj7I/kK
hNPyTZwH/0YpnVlYjvVotjUF9HIcPzp8KLw4aFP8CeXBVRPQDseLoZ+gVwEG21jk
koGig8qYOYRox5XY/K6C2W8zsDRqXK3czUv+CZe5LLjM/yvhgYM=
=NQBq
-----END PGP SIGNATURE-----
Reply to: