Bug #67867 [Com]: php.net is vulnerable to CVE-2014-0224 and exploitable
| From: | jacob dot bednarz at gmail dot com | Date: | Sun, 28 Dec 2014 02:01:10 +0000 |
| Subject: | Bug #67867 [Com]: php.net is vulnerable to CVE-2014-0224 and exploitable | ||
| References: | 1 | Groups: | php.webmaster |
| Request: | Send a blank email to php-webmaster+get-20403@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=67867&edit=1
ID: 67867
Comment by: jacob dot bednarz at gmail dot com
Reported by: fn84b at outlook dot com
Summary: php.net is vulnerable to CVE-2014-0224 and
exploitable
Status: Verified
Type: Bug
Package: Website problem
Operating System: Irrelevant
PHP Version: Irrelevant
Block user comment: N
Private report: N
New Comment:
Can confirm this is showing as fixed for me. Is this one ok to close now?
Previous Comments:
------------------------------------------------------------------------
[2014-08-20 19:01:13] bjori@php.net
php.net and wiki.php.net are now fixed.
master and bugs need to be updated.
------------------------------------------------------------------------
[2014-08-19 20:12:42] fn84b at outlook dot com
Also bugs.php.net "is vulnerable to the OpenSSL CCS vulnerability (CVE-2014-0224), but probably
not exploitable."
https://www.ssllabs.com/ssltest/analyze.html?d=bugs.php.net
------------------------------------------------------------------------
[2014-08-19 20:05:00] fn84b at outlook dot com
Description:
------------
Qualys SSL Labs says php.net server "is vulnerable to the OpenSSL CCS vulnerability
(CVE-2014-0224) and exploitable". So please fix it.
https://www.ssllabs.com/ssltest/analyze.html?d=php.net
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=67867&edit=1