Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:14525
HistoryMay 02, 2019 - 4:52 a.m.

Man-in-the-Middle (MitM)

2019-05-0204:52:37
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

0.029 Low

EPSS

Percentile

90.8%

php is vulnerable to man-in-the-middle attacks. A flaw was found in PHP’s SSL client’s hostname identity check when handling certificates that contain hostnames with NULL bytes. If an attacker was able to get a carefully crafted certificate signed by a trusted Certificate Authority, the attacker could use the certificate to conduct man-in-the-middle attacks to spoof SSL servers.

References