PublicDateAtUSN: 2011-03-19 Candidate: CVE-2011-1468 PublicDate: 2011-03-20 02:00:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1468 https://ubuntu.com/security/notices/USN-1126-1 Description: Multiple memory leaks in the OpenSSL extension in PHP before 5.3.6 might allow remote attackers to cause a denial of service (memory consumption) via (1) plaintext data to the openssl_encrypt function or (2) ciphertext data to the openssl_decrypt function. Ubuntu-Description: Notes: sbeattie> openssl_{en,de}crypt are not available in php 5.2.x. There sbeattie> are possibly other memory leaks in php 5.2.x openssl code. Bugs: http://bugs.php.net/bug.php?id=54060 http://bugs.php.net/bug.php?id=54061 Priority: medium Discovered-by: Assigned-to: sbeattie CVSS: Patches_php5: upstream: http://svn.php.net/viewvc?view=revision&revision=308531 upstream: http://svn.php.net/viewvc?view=revision&revision=308532 upstream: http://svn.php.net/viewvc?view=revision&revision=308533 upstream: http://svn.php.net/viewvc?view=revision&revision=308534 upstream_php5: released (5.3.6) dapper_php5: not-affected hardy_php5: not-affected karmic_php5: not-affected lucid_php5: released (5.3.2-1ubuntu4.8) maverick_php5: released (5.3.3-1ubuntu9.4) natty_php5: released (5.3.5-1ubuntu7.1) devel_php5: not-affected (5.3.5-1ubuntu7.2)