CVE-2011-1468 describes multiple memory leak vulnerabilities in the OpenSSL extension within PHP versions prior to 5.3.6. These flaws could allow remote attackers to trigger a denial of service by consuming memory when processing either plaintext data via the openssl_encrypt function or ciphertext data via the openssl_decrypt function. With a CVSS score of 4.3 (medium severity), successful exploitation requires medium attack complexity and results in partial availability impact. While not actively exploited in the wild and not on the KEV catalog, public exploit code exists on ExploitDB, though there is minimal community discussion or media coverage surrounding this decade-old vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 5.3.5CPE matchmatch criteria | cpe:2.3:a:php:php:*:*:*:*:*:*:*:* | ||
1.0CPE matchmatch criteria | cpe:2.3:a:php:php:1.0:*:*:*:*:*:*:* | ||
2.0CPE matchmatch criteria | cpe:2.3:a:php:php:2.0:*:*:*:*:*:*:* | ||
2.0b10CPE matchmatch criteria | cpe:2.3:a:php:php:2.0b10:*:*:*:*:*:*:* | ||
3.0CPE matchmatch criteria | cpe:2.3:a:php:php:3.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.