PHP 'openssl_encrypt()' Function Information Disclosure Vulnerability
BID:57462
Info
PHP 'openssl_encrypt()' Function Information Disclosure Vulnerability
| Bugtraq ID: | 57462 |
| Class: | Design Error |
| CVE: |
CVE-2012-6113 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 15 2013 12:00AM |
| Updated: | Jan 15 2013 12:00AM |
| Credit: | attb2 |
| Vulnerable: |
PHP PHP 5.3.13 PHP PHP 5.3.12 PHP PHP 5.3.9 PHP PHP 5.3.11 PHP PHP 5.3.10 |
| Not Vulnerable: | |
Discussion
PHP 'openssl_encrypt()' Function Information Disclosure Vulnerability
PHP is prone to an information-disclosure vulnerability that lets attackers retrieve the contents of arbitrary memory locations.
Attackers can exploit this issue to obtain sensitive information that may lead to further attacks.
PHP is prone to an information-disclosure vulnerability that lets attackers retrieve the contents of arbitrary memory locations.
Attackers can exploit this issue to obtain sensitive information that may lead to further attacks.
Exploit / POC
PHP 'openssl_encrypt()' Function Information Disclosure Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: vuldb@securityfocus.
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: vuldb@securityfocus.
Solution / Fix
PHP 'openssl_encrypt()' Function Information Disclosure Vulnerability
Solution:
Vendor updates are available. Please see the references for details.
Solution:
Vendor updates are available. Please see the references for details.
References
PHP 'openssl_encrypt()' Function Information Disclosure Vulnerability
References:
References:
- PHP Homepage (PHP)