Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2009-3291

Published: 22 September 2009

The php_openssl_apply_verification_policy function in PHP before 5.2.11 does not properly perform certificate validation, which has unknown impact and attack vectors, probably related to an ability to spoof certificates.

Notes

AuthorNote
mdeslaur
NUL ('\0') character embedded in X509 certificate's CommonName or subjectAltName
given RH's analysis of this issue, reprioritizing as "low"

Priority

Low

Status

Package Release Status
php5
Launchpad, Ubuntu, Debian
dapper
Released (5.1.2-1ubuntu3.17)
hardy
Released (5.2.4-2ubuntu5.9)
intrepid
Released (5.2.6-2ubuntu4.5)
jaunty
Released (5.2.6.dfsg.1-3ubuntu4.4)
karmic
Released (5.2.10.dfsg.1-2ubuntu6.3)
upstream
Released (5.2.11)
Patches:
upstream: http://svn.php.net/viewvc?view=revision&revision=288329