Infinite Loop Vulnerability in phpseclib Affected by Composite Primefields
CVE-2023-27560

7.5HIGH

Key Information:

Vendor

PHPseclib

Status
Vendor
CVE Published:
3 March 2023

What is CVE-2023-27560?

In versions prior to 3.0.19 of phpseclib, a vulnerability exists in the Math/PrimeField.php file that may cause an infinite loop when dealing with composite primefields. This behavior can lead to performance degradation and potential application unresponsiveness, making it essential for users to update to the latest version to mitigate the risks associated with this vulnerability. For more information, refer to the official release notes and commits detailing the fix.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.