[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 4670-1] php-phpseclib security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

- -----------------------------------------------------------------------
Debian LTS Advisory DLA-4670-1              debian-lts@lists.debian.org
https://www.debian.org/lts/security/                      Utkarsh Gupta
July 05, 2026                               https://wiki.debian.org/LTS
- -----------------------------------------------------------------------

Package        : php-phpseclib
Version        : 2.0.30-2+deb11u3
CVE ID         : CVE-2023-52892 CVE-2026-32935 CVE-2026-40194
                 CVE-2026-44167 CVE-2026-55599
Debian Bug     : 1131483

Several vulnerabilities were discovered in phpseclib, a PHP secure
communications library, which could result in hostname validation
bypass, timing side-channel attacks, denial of service, and
server-side request forgery (SSRF).

CVE-2023-52892

    X509.php did not properly escape regular expression special
    characters in a certificate's subjectAltName, allowing a crafted
    certificate to bypass hostname validation in validateURL().

CVE-2026-32935

    The block cipher unpadding routine in Crypt/Base.php used a
    short-circuiting comparison, creating a timing side channel that
    could aid padding-oracle-style attacks.

CVE-2026-40194

    The SSH2 implementation compared incoming packet HMACs using a
    variable-time string comparison, creating a timing side channel
    on cryptographic material.

CVE-2026-44167

    The ASN.1 decoder's 4096-byte Object Identifier limit (mitigating
    CVE-2024-27355) was still large enough to allow an "OID
    amplification" denial of service via crafted ASN.1 structures.

CVE-2026-55599

    File_X509 could automatically fetch a URL from a certificate's
    Authority Information Access extension without validating the
    destination, allowing SSRF via a crafted certificate.

For Debian 11 bullseye, these problems have been fixed in version
2.0.30-2+deb11u3.

We recommend that you upgrade your php-phpseclib packages.

For the detailed security status of php-phpseclib please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/php-phpseclib

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEbJ0QSEqa5Mw4X3xxgj6WdgbDS5YFAmpJX4sACgkQgj6WdgbD
S5aGmhAApDNuC1UmF+a+1SEZB16ugTc+/wo8nk+gP3n00aN2sG1FpB1k1yR5x1Y4
QW9SPgPftYcEFT9p1I1zGC0AOXHC091BfrOeKN2glgJuknqvY6qdG92qxA3jkwxh
3DinrIRO5Oq+EaKH7NdcYhOANXA6S3LCny3gio6I+qfPR7RBbxFYrM73VpAgYu1e
9D0T6Qx2ypHINEhz3NYOTGmmDsG1c6uSuQLrMF8Gx5BJwoeGgCv4GA5LmZDbgw5y
2O66wFMXJGAGvpuH1qB/eKXAUu/nocHi9yIAWeUcYMYDZdnChaHnM/VIX4lpXqWu
CmiNxS5/VlcZ/INteL7iujHXmPvnGz3nc3qwMy5rh8Pm4hAD5Dx5uMe176v5zFWC
4/CgvrWVWI1zTufwFNZAuA1cwXRAwBqXhYT1pgGxd/eHUHMmBEoSmUsQPJ3sJ6uW
nDiJq0zvWrDs9tQ+hKH5cmnHUM46VKUfNAdcZ+mnPE2X31chSQJ54wKGHV2VQBRY
ndZHL5T883ELCzxsF1ksJNjIUgidHDTTIOc0VRHbzNuFrxHeoGxGO5eF0Bj7I/kK
hNPyTZwH/0YpnVlYjvVotjUF9HIcPzp8KLw4aFP8CeXBVRPQDseLoZ+gVwEG21jk
koGig8qYOYRox5XY/K6C2W8zsDRqXK3czUv+CZe5LLjM/yvhgYM=
=NQBq
-----END PGP SIGNATURE-----


Reply to: