MGASA-2013-0264

Source
https://advisories.mageia.org/MGASA-2013-0264.html
Import Source
https://advisories.mageia.org/MGASA-2013-0264.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2013-0264
Upstream
  • CVE-2013-4248
Published
2013-08-30T17:30:10Z
Modified
2026-04-16T06:23:03.497352300Z
Summary
Updated php packages fix CVE-2013-4248 and prevent the two gd packages being installed at once
Details

Updated php packages fix security vulnerability:

The opensslx509parse function in openssl.c in the OpenSSL module in PHP before 5.4.18 and 5.5.x before 5.5.2 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority (CVE-2013-4248).

Additionally it prevents php-gd and php-gd-bundled packages being installed at the same time, which causes errors.

References
Credits

Affected packages

Mageia:2 / php

Package

Name
php
Purl
pkg:rpm/mageia/php?arch=source&distro=mageia-2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.3.27-1.2.mga2

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2013-0264.json"

Mageia:3 / php

Package

Name
php
Purl
pkg:rpm/mageia/php?arch=source&distro=mageia-3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.4.19-1.1.mga3

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2013-0264.json"

Mageia:3 / php-apc

Package

Name
php-apc
Purl
pkg:rpm/mageia/php-apc?arch=source&distro=mageia-3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.1.14-7.3.mga3

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2013-0264.json"

Mageia:3 / php-gd-bundled

Package

Name
php-gd-bundled
Purl
pkg:rpm/mageia/php-gd-bundled?arch=source&distro=mageia-3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.4.19-1.mga3

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2013-0264.json"