Fedora Account System
Red Hat Associate
Red Hat Customer
An issue was discovered in phpseclib 1.x before 1.0.23, 2.x before 2.0.47, and 3.x before 3.0.36. When processing the ASN.1 object identifier of a certificate, a sub identifier may be provided that leads to a denial of service (CPU consumption for decodeOID). https://gist.github.com/katzj/ee72f3c2a00590812b2ea3c0c8890e0b https://github.com/phpseclib/phpseclib/blob/978d081fe50ff92879c50ff143c62a143edb0117/phpseclib/File/ASN1.php#L1129
Created php-phpseclib tracking bugs for this issue: Affects: epel-all [bug 2267502] Affects: fedora-all [bug 2267501]