terrafrost
5 exploits
Active since Mar 2023
phpseclib has a variable-time HMAC comparison in SSH2::get_binary_packet() using != instead of hash_equals()
CVSS 3.7
phpseclib's AES-CBC unpadding susceptible to padding oracle timing attack
Phpseclib < 3.0.19 - Infinite Loop
CVSS 7.5
phpseclib <3.0.34 - DoS
CVSS 7.5
Phpseclib < 1.0.22 - Interpretation Conflict
CVSS 7.5