CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
Percentile
85.1%
The php_openssl_apply_verification_policy function in PHP before 5.2.11
does not properly perform certificate validation, which has unknown impact
and attack vectors, probably related to an ability to spoof certificates.
Author | Note |
---|---|
mdeslaur | NUL (‘\0’) character embedded in X509 certificate’s CommonName or subjectAltName given RH’s analysis of this issue, reprioritizing as “low” |