Description
Math/PrimeField.php in phpseclib 3.x before 3.0.19 has an infinite loop with composite primefields.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6Attack Vector: Network
Complexity: Low
Privileges: None
User Interaction: None
Scope: Unchanged
Confidentiality: None
Integrity: None
Availability: High
Affected Packages6 packages
Also affects: Debian Linux 10.0
🔴Vulnerability Details
6OSVphpseclib a large prime can cause a denial of service↗2024-03-02 ▶ GHSAphpseclib a large prime can cause a denial of service↗2024-03-02 ▶ OSVCVE-2024-27354: An issue was discovered in phpseclib 1↗2024-03-01 ▶ OSVCVE-2023-27560: Math/PrimeField↗2023-03-03 ▶ GHSAphpseclib Infinite Loop vulnerability↗2023-03-03 ▶ 📋Vendor Advisories
2DebianCVE-2024-27354: php-phpseclib - An issue was discovered in phpseclib 1.x before 1.0.23, 2.x before 2.0.47, and 3...↗2024 ▶ DebianCVE-2023-27560: php-phpseclib3 - Math/PrimeField.php in phpseclib 3.x before 3.0.19 has an infinite loop with com...↗2023 ▶