// For flags

CVE-2013-6420

PHP - 'openssl_x509_parse()' Memory Corruption

Severity Score

7.5
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The asn1_time_to_time_t function in ext/openssl/openssl.c in PHP before 5.3.28, 5.4.x before 5.4.23, and 5.5.x before 5.5.7 does not properly parse (1) notBefore and (2) notAfter timestamps in X.509 certificates, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted certificate that is not properly handled by the openssl_x509_parse function.

La función asn1_time_to_time_t en ext / openssl / openssl.c en PHP anterior a 5.3.28, 5.4.x aterior a 5.4.23 y 5.5.x anterior de 5.5.7 no trata correctamente las marcas de tiempo (timestamps) (1) notBefore y (2) notAfter en certificados X 0.509 , lo que permite a atacantes remotos ejecutar código arbitrario o causar una denegación de servicio (corrupción de memoria) a través de un certificado manipulado que no está tratado adecuadamente por la función openssl_x509_parse.

The PHP function openssl_x509_parse() uses a helper function called asn1_time_to_time_t() to convert timestamps from ASN1 string format into integer timestamp values. The parser within this helper function is not binary safe and can therefore be tricked to write up to five NUL bytes outside of an allocated buffer. This problem can be triggered by x509 certificates that contain NUL bytes in their notBefore and notAfter timestamp fields and leads to a memory corruption that might result in arbitrary code execution.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2013-11-04 CVE Reserved
  • 2013-12-11 CVE Published
  • 2013-12-17 First Exploit
  • 2023-12-15 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (21)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.0
Search vendor "Php" for product "Php" and version "5.4.0"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.1
Search vendor "Php" for product "Php" and version "5.4.1"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.2
Search vendor "Php" for product "Php" and version "5.4.2"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.3
Search vendor "Php" for product "Php" and version "5.4.3"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.4
Search vendor "Php" for product "Php" and version "5.4.4"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.5
Search vendor "Php" for product "Php" and version "5.4.5"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.6
Search vendor "Php" for product "Php" and version "5.4.6"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.7
Search vendor "Php" for product "Php" and version "5.4.7"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.8
Search vendor "Php" for product "Php" and version "5.4.8"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.9
Search vendor "Php" for product "Php" and version "5.4.9"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.10
Search vendor "Php" for product "Php" and version "5.4.10"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.11
Search vendor "Php" for product "Php" and version "5.4.11"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.12
Search vendor "Php" for product "Php" and version "5.4.12"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.12
Search vendor "Php" for product "Php" and version "5.4.12"
rc1
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.12
Search vendor "Php" for product "Php" and version "5.4.12"
rc2
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.13
Search vendor "Php" for product "Php" and version "5.4.13"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.13
Search vendor "Php" for product "Php" and version "5.4.13"
rc1
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.14
Search vendor "Php" for product "Php" and version "5.4.14"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.14
Search vendor "Php" for product "Php" and version "5.4.14"
rc1
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.15
Search vendor "Php" for product "Php" and version "5.4.15"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.15
Search vendor "Php" for product "Php" and version "5.4.15"
rc1
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.16
Search vendor "Php" for product "Php" and version "5.4.16"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.16
Search vendor "Php" for product "Php" and version "5.4.16"
rc1
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.17
Search vendor "Php" for product "Php" and version "5.4.17"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.18
Search vendor "Php" for product "Php" and version "5.4.18"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.19
Search vendor "Php" for product "Php" and version "5.4.19"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.20
Search vendor "Php" for product "Php" and version "5.4.20"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.21
Search vendor "Php" for product "Php" and version "5.4.21"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.4.22
Search vendor "Php" for product "Php" and version "5.4.22"
-
Affected
Opensuse
Search vendor "Opensuse"
Opensuse
Search vendor "Opensuse" for product "Opensuse"
11.4
Search vendor "Opensuse" for product "Opensuse" and version "11.4"
-
Affected
Opensuse
Search vendor "Opensuse"
Opensuse
Search vendor "Opensuse" for product "Opensuse"
12.2
Search vendor "Opensuse" for product "Opensuse" and version "12.2"
-
Affected
Opensuse
Search vendor "Opensuse"
Opensuse
Search vendor "Opensuse" for product "Opensuse"
12.3
Search vendor "Opensuse" for product "Opensuse" and version "12.3"
-
Affected
Opensuse
Search vendor "Opensuse"
Opensuse
Search vendor "Opensuse" for product "Opensuse"
13.1
Search vendor "Opensuse" for product "Opensuse" and version "13.1"
-
Affected
Apple
Search vendor "Apple"
Mac Os X
Search vendor "Apple" for product "Mac Os X"
<= 10.9.1
Search vendor "Apple" for product "Mac Os X" and version " <= 10.9.1"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
<= 5.3.27
Search vendor "Php" for product "Php" and version " <= 5.3.27"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.3.0
Search vendor "Php" for product "Php" and version "5.3.0"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.3.1
Search vendor "Php" for product "Php" and version "5.3.1"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.3.2
Search vendor "Php" for product "Php" and version "5.3.2"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.3.3
Search vendor "Php" for product "Php" and version "5.3.3"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.3.4
Search vendor "Php" for product "Php" and version "5.3.4"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.3.5
Search vendor "Php" for product "Php" and version "5.3.5"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.3.6
Search vendor "Php" for product "Php" and version "5.3.6"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.3.7
Search vendor "Php" for product "Php" and version "5.3.7"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.3.8
Search vendor "Php" for product "Php" and version "5.3.8"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.3.9
Search vendor "Php" for product "Php" and version "5.3.9"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.3.10
Search vendor "Php" for product "Php" and version "5.3.10"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.3.11
Search vendor "Php" for product "Php" and version "5.3.11"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.3.12
Search vendor "Php" for product "Php" and version "5.3.12"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.3.13
Search vendor "Php" for product "Php" and version "5.3.13"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.3.14
Search vendor "Php" for product "Php" and version "5.3.14"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.3.15
Search vendor "Php" for product "Php" and version "5.3.15"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.3.16
Search vendor "Php" for product "Php" and version "5.3.16"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.3.17
Search vendor "Php" for product "Php" and version "5.3.17"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.3.18
Search vendor "Php" for product "Php" and version "5.3.18"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.3.19
Search vendor "Php" for product "Php" and version "5.3.19"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.3.20
Search vendor "Php" for product "Php" and version "5.3.20"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.3.21
Search vendor "Php" for product "Php" and version "5.3.21"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.3.22
Search vendor "Php" for product "Php" and version "5.3.22"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.3.23
Search vendor "Php" for product "Php" and version "5.3.23"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.3.24
Search vendor "Php" for product "Php" and version "5.3.24"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.3.25
Search vendor "Php" for product "Php" and version "5.3.25"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.3.26
Search vendor "Php" for product "Php" and version "5.3.26"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.0
Search vendor "Php" for product "Php" and version "5.5.0"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.0
Search vendor "Php" for product "Php" and version "5.5.0"
alpha1
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.0
Search vendor "Php" for product "Php" and version "5.5.0"
alpha2
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.0
Search vendor "Php" for product "Php" and version "5.5.0"
alpha3
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.0
Search vendor "Php" for product "Php" and version "5.5.0"
alpha4
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.0
Search vendor "Php" for product "Php" and version "5.5.0"
alpha5
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.0
Search vendor "Php" for product "Php" and version "5.5.0"
alpha6
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.0
Search vendor "Php" for product "Php" and version "5.5.0"
beta1
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.0
Search vendor "Php" for product "Php" and version "5.5.0"
beta2
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.0
Search vendor "Php" for product "Php" and version "5.5.0"
beta3
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.0
Search vendor "Php" for product "Php" and version "5.5.0"
beta4
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.0
Search vendor "Php" for product "Php" and version "5.5.0"
rc1
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.0
Search vendor "Php" for product "Php" and version "5.5.0"
rc2
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.1
Search vendor "Php" for product "Php" and version "5.5.1"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.2
Search vendor "Php" for product "Php" and version "5.5.2"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.3
Search vendor "Php" for product "Php" and version "5.5.3"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.4
Search vendor "Php" for product "Php" and version "5.5.4"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.5
Search vendor "Php" for product "Php" and version "5.5.5"
-
Affected
Php
Search vendor "Php"
Php
Search vendor "Php" for product "Php"
5.5.6
Search vendor "Php" for product "Php" and version "5.5.6"
-
Affected