phpseclib
cpe:2.3:a:phpseclib:phpseclib:*:*:*:*:*:*:*
- >= 3.0.0, <= 3.0.51
- >= 2.0.0, <= 2.0.53
- >= 0.1.1, <= 1.0.28
A denial-of-service vulnerability has been identified in phpseclib, a PHP library for secure communications. This issue affects versions 1.0.0 prior to 1.0.29, 2.0.0 prior to 2.0.54, and 3.0.0 prior to 3.0.52. The vulnerability arises in the ASN.1 decoding function, where the library improperly handles untrusted ASN.1 files, such as X.509 certificates and RSA PKCS#8 keys. This mismanagement can lead to excessive resource consumption, causing a denial-of-service condition.
Exploitation of this vulnerability can cause a significant denial-of-service condition by overloading the system's resources.
Users can upgrade to phpseclib versions 1.0.29, 2.0.54, or 3.0.52 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.