Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:23980
HistoryApr 10, 2020 - 12:42 a.m.

Spoofing Attack

2020-04-1000:42:39
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

EPSS

0.012

Percentile

85.1%

php is vulnerable to spoofing attacks. It was discovered that PHP was affected by the previously published “null prefix attack”, caused by incorrect handling of NUL characters in X.509 certificates. If an attacker is able to get a carefully-crafted certificate signed by a trusted Certificate Authority, the attacker could use the certificate during a man-in-the-middle attack and potentially confuse PHP into accepting it by mistake.

References