CVE-2011-1468
Publication date 19 March 2011
Last updated 24 July 2024
Ubuntu priority
Description
Multiple memory leaks in the OpenSSL extension in PHP before 5.3.6 might allow remote attackers to cause a denial of service (memory consumption) via (1) plaintext data to the openssl_encrypt function or (2) ciphertext data to the openssl_decrypt function.
Status
Package | Ubuntu Release | Status |
---|---|---|
php5 | ||
Notes
sbeattie
openssl_{en,de}crypt are not available in php 5.2.x. There are possibly other memory leaks in php 5.2.x openssl code.
Patch details
Package | Patch details |
---|---|
php5 |
References
Related Ubuntu Security Notices (USN)
- USN-1126-1
- PHP vulnerabilities
- 29 April 2011