phpseclib is a PHP secure communications library. Projects using versions 1.0.26 and below, 2.0.0 through 2.0.51, and 3.0.0 through 3.0.49 are vulnerable to a to padding oracle timing attack when using AES in CBC mode. This issue has been fixed in versions 1.0.27, 2.0.52 and 3.0.50.
Attack Parameters
Impact Assessment
CVSS Vector v4.0
Weakness Type (CWE)
Vulnerable Products 3
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Phpseclib Phpseclib
cpe:2.3:a:phpseclib:phpseclib:*:*:*:*:*:*:*:*
|
— |
1.0.27
|
|
Phpseclib Phpseclib
cpe:2.3:a:phpseclib:phpseclib:*:*:*:*:*:*:*:*
|
2.0.0
|
2.0.52
|
|
Phpseclib Phpseclib
cpe:2.3:a:phpseclib:phpseclib:*:*:*:*:*:*:*:*
|
3.0.0
|
3.0.50
|