|
|
Log in / Subscribe / Register

Debian alert DLA-4670-1 (php-phpseclib)

From:  Utkarsh Gupta <utkarsh@debian.org>
To:  debian-lts-announce@lists.debian.org
Subject:  [SECURITY] [DLA 4670-1] php-phpseclib security update
Date:  Sun, 05 Jul 2026 01:01:48 +0530
Message-ID:  <CAPP0f97q0VhfSbgwE5kAthQUen_=qRXNR1P9dUUY-F7Ks52t1g@mail.gmail.com>

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ----------------------------------------------------------------------- Debian LTS Advisory DLA-4670-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Utkarsh Gupta July 05, 2026 https://wiki.debian.org/LTS - ----------------------------------------------------------------------- Package : php-phpseclib Version : 2.0.30-2+deb11u3 CVE ID : CVE-2023-52892 CVE-2026-32935 CVE-2026-40194 CVE-2026-44167 CVE-2026-55599 Debian Bug : 1131483 Several vulnerabilities were discovered in phpseclib, a PHP secure communications library, which could result in hostname validation bypass, timing side-channel attacks, denial of service, and server-side request forgery (SSRF). CVE-2023-52892 X509.php did not properly escape regular expression special characters in a certificate's subjectAltName, allowing a crafted certificate to bypass hostname validation in validateURL(). CVE-2026-32935 The block cipher unpadding routine in Crypt/Base.php used a short-circuiting comparison, creating a timing side channel that could aid padding-oracle-style attacks. CVE-2026-40194 The SSH2 implementation compared incoming packet HMACs using a variable-time string comparison, creating a timing side channel on cryptographic material. CVE-2026-44167 The ASN.1 decoder's 4096-byte Object Identifier limit (mitigating CVE-2024-27355) was still large enough to allow an "OID amplification" denial of service via crafted ASN.1 structures. CVE-2026-55599 File_X509 could automatically fetch a URL from a certificate's Authority Information Access extension without validating the destination, allowing SSRF via a crafted certificate. For Debian 11 bullseye, these problems have been fixed in version 2.0.30-2+deb11u3. We recommend that you upgrade your php-phpseclib packages. For the detailed security status of php-phpseclib please refer to its security tracker page at: https://security-tracker.debian.org/tracker/php-phpseclib Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEbJ0QSEqa5Mw4X3xxgj6WdgbDS5YFAmpJX4sACgkQgj6WdgbD S5aGmhAApDNuC1UmF+a+1SEZB16ugTc+/wo8nk+gP3n00aN2sG1FpB1k1yR5x1Y4 QW9SPgPftYcEFT9p1I1zGC0AOXHC091BfrOeKN2glgJuknqvY6qdG92qxA3jkwxh 3DinrIRO5Oq+EaKH7NdcYhOANXA6S3LCny3gio6I+qfPR7RBbxFYrM73VpAgYu1e 9D0T6Qx2ypHINEhz3NYOTGmmDsG1c6uSuQLrMF8Gx5BJwoeGgCv4GA5LmZDbgw5y 2O66wFMXJGAGvpuH1qB/eKXAUu/nocHi9yIAWeUcYMYDZdnChaHnM/VIX4lpXqWu CmiNxS5/VlcZ/INteL7iujHXmPvnGz3nc3qwMy5rh8Pm4hAD5Dx5uMe176v5zFWC 4/CgvrWVWI1zTufwFNZAuA1cwXRAwBqXhYT1pgGxd/eHUHMmBEoSmUsQPJ3sJ6uW nDiJq0zvWrDs9tQ+hKH5cmnHUM46VKUfNAdcZ+mnPE2X31chSQJ54wKGHV2VQBRY ndZHL5T883ELCzxsF1ksJNjIUgidHDTTIOc0VRHbzNuFrxHeoGxGO5eF0Bj7I/kK hNPyTZwH/0YpnVlYjvVotjUF9HIcPzp8KLw4aFP8CeXBVRPQDseLoZ+gVwEG21jk koGig8qYOYRox5XY/K6C2W8zsDRqXK3czUv+CZe5LLjM/yvhgYM= =NQBq -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds