CVE
- Id
- 40726
- CVE No.
- CVE-2009-3291
- Status
- Candidate
- Description
- The php_openssl_apply_verification_policy function in PHP before 5.2.11 does not properly perform certificate validation, which has unknown impact and attack vectors, probably related to an ability to spoof certificates.
- Phase
- Assigned (20090922)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
446694 | 40726 | CVE-2009-3291 | CONFIRM:http://www.php.net/ChangeLog-5.php#5.2.11 | View |
446695 | 40726 | CVE-2009-3291 | CONFIRM:http://www.php.net/releases/5_2_11.php | View |
446696 | 40726 | CVE-2009-3291 | CONFIRM:http://support.apple.com/kb/HT3937 | View |
446697 | 40726 | CVE-2009-3291 | APPLE:APPLE-SA-2009-11-09-1 | View |
446698 | 40726 | CVE-2009-3291 | URL:http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html | View |
446699 | 40726 | CVE-2009-3291 | DEBIAN:DSA-1940 | View |
446700 | 40726 | CVE-2009-3291 | URL:http://www.debian.org/security/2009/dsa-1940 | View |
446701 | 40726 | CVE-2009-3291 | HP:HPSBUX02543 | View |
446702 | 40726 | CVE-2009-3291 | URL:http://marc.info/?l=bugtraq&m=127680701405735&w=2 | View |
446703 | 40726 | CVE-2009-3291 | HP:SSRT100152 | View |
446704 | 40726 | CVE-2009-3291 | URL:http://marc.info/?l=bugtraq&m=127680701405735&w=2 | View |
446705 | 40726 | CVE-2009-3291 | HP:HPSBOV02683 | View |
446706 | 40726 | CVE-2009-3291 | URL:http://marc.info/?l=bugtraq&m=130497311408250&w=2 | View |
446707 | 40726 | CVE-2009-3291 | HP:SSRT090208 | View |
446708 | 40726 | CVE-2009-3291 | URL:http://marc.info/?l=bugtraq&m=130497311408250&w=2 | View |
446709 | 40726 | CVE-2009-3291 | SUSE:SUSE-SR:2009:017 | View |
446710 | 40726 | CVE-2009-3291 | URL:http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00004.html | View |
446711 | 40726 | CVE-2009-3291 | OSVDB:58185 | View |
446712 | 40726 | CVE-2009-3291 | URL:http://www.osvdb.org/58185 | View |
446713 | 40726 | CVE-2009-3291 | OVAL:oval:org.mitre.oval:def:10438 | View |
446714 | 40726 | CVE-2009-3291 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10438 | View |
446715 | 40726 | CVE-2009-3291 | OVAL:oval:org.mitre.oval:def:7394 | View |
446716 | 40726 | CVE-2009-3291 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7394 | View |
446717 | 40726 | CVE-2009-3291 | SECTRACK:1022914 | View |
446718 | 40726 | CVE-2009-3291 | URL:http://www.securitytracker.com/id?1022914 | View |
446719 | 40726 | CVE-2009-3291 | SECUNIA:36791 | View |
446720 | 40726 | CVE-2009-3291 | URL:http://secunia.com/advisories/36791 | View |
446721 | 40726 | CVE-2009-3291 | SECUNIA:37482 | View |
446722 | 40726 | CVE-2009-3291 | URL:http://secunia.com/advisories/37482 | View |
446723 | 40726 | CVE-2009-3291 | SECUNIA:40262 | View |
446724 | 40726 | CVE-2009-3291 | URL:http://secunia.com/advisories/40262 | View |
446725 | 40726 | CVE-2009-3291 | VUPEN:ADV-2009-3184 | View |
446726 | 40726 | CVE-2009-3291 | URL:http://www.vupen.com/english/advisories/2009/3184 | View |
446727 | 40726 | CVE-2009-3291 | XF:php-certificate-unspecified(53334) | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
43960 | JVNDB-2009-004967 | MIT Kerberos の prep_reprocess_req 関数におけるサービス運用妨害 (DoS) の脆弱性 | MIT Kerberos の Key Distribution Center (KDC) のクロスレルムリファーラル実装の kdc/do_tgs_req.c の prep_reprocess_req 関数には、サービス運用妨害 (NULL ポインタデリファレンスおよびデーモンクラッシュ) 状態となる脆弱性が存在します。 | CVE-2009-3295 | 40726 | 5 | http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-004967.html | View |