Description
The php_openssl_apply_verification_policy function in PHP before 5.2.11 does not properly perform certificate validation, which has unknown impact and attack vectors, probably related to an ability to spoof certificates.
Remediation
References
Related Vulnerabilities
MySQL CVE-2022-21256 Vulnerability (CVE-2022-21256)
Oracle Application Server CVE-2006-3714 Vulnerability (CVE-2006-3714)
Envoy Proxy Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2019-15225)
ATutor Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-3706)