CVE-2013-6420
high
CVSS v3
—
CVSS v2
7.5
VIR risk
8.5
Description
The asn1_time_to_time_t function in ext/openssl/openssl.c in PHP before 5.3.28, 5.4.x before 5.4.23, and 5.5.x before 5.5.7 does not properly parse (1) notBefore and (2) notAfter timestamps in X.509 certificates, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted certificate that is not properly handled by the openssl_x509_parse function.
Predictions
Exploit likelihood
55%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: secalert@redhat.com — https://bugzilla.redhat.com/show_bug.cgi?id=1036830
Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2013-6420.html
Exploits
Exploit-DB
- EDB-30395 · dos · php
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| sles | affected | | |
| suse | 11.4 | affected | |
| suse | 12.2 | affected | |
| suse | 12.3 | affected | |
| suse | 13.1 | affected | |
| macos | affected | |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| php | php | 5.4.0 | |
| php | php | 5.4.1 | |
| php | php | 5.4.2 | |
| php | php | 5.4.3 | |
| php | php | 5.4.4 | |
| php | php | 5.4.5 | |
| php | php | 5.4.6 | |
| php | php | 5.4.7 | |
| php | php | 5.4.8 | |
| php | php | 5.4.9 | |
| php | php | 5.4.10 | |
| php | php | 5.4.11 | |
| php | php | 5.4.12 | |
| php | php | 5.4.13 | |
| php | php | 5.4.14 | |
| php | php | 5.4.15 | |
| php | php | 5.4.16 | |
| php | php | 5.4.17 | |
| php | php | 5.4.18 | |
| php | php | 5.4.19 | |
| php | php | 5.4.20 | |
| php | php | 5.4.21 | |
| php | php | 5.4.22 | |
| php | php | {"endIncluding":"5.3.27"} | |
| php | php | 5.3.0 | |
| php | php | 5.3.1 | |
| php | php | 5.3.2 | |
| php | php | 5.3.3 | |
| php | php | 5.3.4 | |
| php | php | 5.3.5 | |
| php | php | 5.3.6 | |
| php | php | 5.3.7 | |
| php | php | 5.3.8 | |
| php | php | 5.3.9 | |
| php | php | 5.3.10 | |
| php | php | 5.3.11 | |
| php | php | 5.3.12 | |
| php | php | 5.3.13 | |
| php | php | 5.3.14 | |
| php | php | 5.3.15 | |
| php | php | 5.3.16 | |
| php | php | 5.3.17 | |
| php | php | 5.3.18 | |
| php | php | 5.3.19 | |
| php | php | 5.3.20 | |
| php | php | 5.3.21 | |
| php | php | 5.3.22 | |
| php | php | 5.3.23 | |
| php | php | 5.3.24 | |
| php | php | 5.3.25 | |
| php | php | 5.3.26 | |
| php | php | 5.5.0 | |
| php | php | 5.5.1 | |
| php | php | 5.5.2 | |
| php | php | 5.5.3 | |
| php | php | 5.5.4 | |
| php | php | 5.5.5 | |
| php | php | 5.5.6 | |
References
- https://www.suse.com/security/cve/CVE-2013-6420.html
- http://forums.interworx.com/threads/8000-InterWorx-Version-5-0-14-Released-on-Beta-Channel%21
- http://git.php.net/?p=php-src.git%3Ba=commit%3Bh=c1224573c773b6845e83505f717fbf820fc18415
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00125.html
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00126.html
- http://rhn.redhat.com/errata/RHSA-2013-1813.html
- http://rhn.redhat.com/errata/RHSA-2013-1815.html
- http://rhn.redhat.com/errata/RHSA-2013-1824.html
- http://rhn.redhat.com/errata/RHSA-2013-1825.html
- http://rhn.redhat.com/errata/RHSA-2013-1826.html
- http://secunia.com/advisories/59652
- http://support.apple.com/kb/HT6150
- http://www.debian.org/security/2013/dsa-2816
- http://www.php.net/ChangeLog-5.php
- http://www.securityfocus.com/bid/64225
- http://www.securitytracker.com/id/1029472
- http://www.ubuntu.com/usn/USN-2055-1
- https://bugzilla.redhat.com/show_bug.cgi?id=1036830
- https://h20564.www2.hp.com/hpsc/doc/public/display?docId=emr_na-c04463322
- https://www.sektioneins.de/advisories/advisory-012013-php-openssl_x509_parse-memory-corruption-vulnerability.html
CWEs
CWE-119
Verify integrity in audit chain (admin only). AS-IS.