7.5
CVSSv2

CVE-2009-3291

Published: 22/09/2009 Updated: 30/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The php_openssl_apply_verification_policy function in PHP prior to 5.2.11 does not properly perform certificate validation, which has unknown impact and attack vectors, probably related to an ability to spoof certificates.

Vulnerable Product Search on Vulmon Subscribe to Product

php php 4.3.6

php php 4.3.5

php php 4.3.0

php php 5.0.0

php php 4.3.7

php php 4.4.4

php php 5.1.0

php php 5.0.2

php php 4.4.9

php php 4.2

php php 3.0.12

php php 3.0.1

php php 3.0.14

php php 3.0.17

php php 3.0.16

php php 3.0.5

php php 3.0.6

php php 4.0

php php 4.0.1

php php 4.1.2

php php 4.0.7

php php 5.2.9

php php 5.2.2

php php 5.2.1

php php

php php 4.3.4

php php 4.3.3

php php 4.2.3

php php 4.2.2

php php 5.0

php php 4.4.2

php php 4.4.3

php php 4.4.8

php php 2.0

php php 3.0.10

php php 3.0.13

php php 3.0.3

php php 3.0.15

php php 3.0.7

php php 3.0.8

php php 4.0.3

php php 4.0.2

php php 5.2.4

php php 5.2.3

php php 5.1.3

php php 5.1.2

php php 5.1.1

php php 4.3.10

php php 4.3.1

php php 4.2.0

php php 4.1.0

php php 4.4.5

php php 4.4.6

php php 4.3.8

php php 4.3.9

php php 5.0.5

php php 5.0.4

php php 5.0.1

php php 5

php php 4

php php 3.0

php php 3.0.2

php php 4.0.6

php php 4.0.5

php php 4.1.1

php php 5.2.8

php php 5.2.7

php php 5.2.0

php php 5.1.6

php php 4.3.2

php php 4.3.11

php php 4.2.1

php php 4.4.7

php php 4.4.0

php php 4.4.1

php php 5.0.3

php php 1.0

php php 2.0b10

php php 3.0.11

php php 3.0.18

php php 3.0.4

php php 3.0.9

php php 4.0.0

php php 4.0.4

php php 5.2.6

php php 5.2.5

php php 5.1.5

php php 5.1.4

Vendor Advisories

Synopsis Moderate: php security update Type/Severity Security Advisory: Moderate Topic Updated php packages that fix several security issues are now available forRed Hat Enterprise Linux 3, 4, and 5This update has been rated as having moderate security impact by the RedHat Security Response Team ...
Maksymilian Arciemowicz discovered that PHP did not properly validate arguments to the dba_replace function If a script passed untrusted input to the dba_replace function, an attacker could truncate the database This issue only applied to Ubuntu 606 LTS, 804 LTS, and 810 (CVE-2008-7068) ...
Debian Bug report logs - #540605 php5: memory disclosure Package: php5; Maintainer for php5 is Debian PHP Maintainers <pkg-php-maint@listsaliothdebianorg>; Source for php5 is src:php5 (PTS, buildd, popcon) Reported by: "Michael S Gilbert" <michaelsgilbert@gmailcom> Date: Sun, 9 Aug 2009 04:30:04 UTC Severity ...
Debian Bug report logs - #535888 php: segfaults on corrupted jpeg files Package: php5; Maintainer for php5 is Debian PHP Maintainers <pkg-php-maint@listsaliothdebianorg>; Source for php5 is src:php5 (PTS, buildd, popcon) Reported by: "Michael S Gilbert" <michaelsgilbert@gmailcom> Date: Sun, 5 Jul 2009 19:57:0 ...