LWN.net Logo

php5: information disclosure

Package(s):php5 CVE #(s):CVE-2012-6113
Created:January 22, 2013 Updated:January 23, 2013
Description: From the CVE entry:

The openssl_encrypt function in ext/openssl/openssl.c in PHP 5.3.9 through 5.3.13 does not initialize a certain variable, which allows remote attackers to obtain sensitive information from process memory by providing zero bytes of input data.

Alerts:
Ubuntu USN-1702-1 2013-01-22

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds