5
CVSSv2

CVE-2012-6113

Published: 19/01/2013 Updated: 13/02/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The openssl_encrypt function in ext/openssl/openssl.c in PHP 5.3.9 up to and including 5.3.13 does not initialize a certain variable, which allows remote malicious users to obtain sensitive information from process memory by providing zero bytes of input data.

Vulnerable Product Search on Vulmon Subscribe to Product

php php 5.3.10

php php 5.3.9

php php 5.3.12

php php 5.3.11

php php 5.3.13

Vendor Advisories

PHP could be made to expose sensitive information over the network ...