CVE-2012-6113
19.01.2013, 21:55
The openssl_encrypt function in ext/openssl/openssl.c in PHP 5.3.9 through 5.3.13 does not initialize a certain variable, which allows remote attackers to obtain sensitive information from process memory by providing zero bytes of input data.Enginsight
Vendor | Product | Version |
---|---|---|
php | php | 5.3.9 |
php | php | 5.3.10 |
php | php | 5.3.11 |
php | php | 5.3.12 |
php | php | 5.3.13 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
References