php is vulnerable to man-in-the-middle attacks. A flaw was found in PHP’s SSL client’s hostname identity check when handling certificates that contain hostnames with NULL bytes. If an attacker was able to get a carefully crafted certificate signed by a trusted Certificate Authority, the attacker could use the certificate to conduct man-in-the-middle attacks to spoof SSL servers.
git.php.net/?p=php-src.git;a=commit;h=2874696a5a8d46639d261571f915c493cd875897
lists.opensuse.org/opensuse-updates/2013-12/msg00125.html
lists.opensuse.org/opensuse-updates/2013-12/msg00126.html
marc.info/?l=bugtraq&m=141390017113542&w=2
rhn.redhat.com/errata/RHSA-2013-1307.html
rhn.redhat.com/errata/RHSA-2013-1615.html
secunia.com/advisories/54478
secunia.com/advisories/54657
secunia.com/advisories/55078
secunia.com/advisories/59652
support.apple.com/kb/HT6150
www.debian.org/security/2013/dsa-2742
www.php.net/ChangeLog-5.php
www.securityfocus.com/bid/61776
www.securitytracker.com/id/1028924
www.ubuntu.com/usn/USN-1937-1
access.redhat.com/security/updates/classification/#moderate
access.redhat.com/site/documentation/en-US/Red_Hat_Enterprise_Linux/5/html/5.10_Technical_Notes/php53.html#RHSA-2013-1307
bugzilla.redhat.com/show_bug.cgi?id=837044
bugzilla.redhat.com/show_bug.cgi?id=869691
bugzilla.redhat.com/show_bug.cgi?id=869693
bugzilla.redhat.com/show_bug.cgi?id=869697
bugzilla.redhat.com/show_bug.cgi?id=892695
bugzilla.redhat.com/show_bug.cgi?id=951075
bugzilla.redhat.com/show_bug.cgi?id=953818
rhn.redhat.com/errata/RHSA-2013-1307.html