DescriptionIn PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when AES-CCM mode is used with openssl_encrypt() function with 12 bytes IV, only first 7 bytes of the IV is actually used. This can lead to both decreased security and incorrect encryption data.
NVD severitymedium

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
php7.0 (PTS)stretch7.0.33-0+deb9u8fixed
stretch (security)7.0.33-0+deb9u10fixed
php7.3 (PTS)buster, buster (security)7.3.19-1~deb10u1vulnerable
php7.4 (PTS)bullseye7.4.11-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
php7.0source(unstable)(not affected)


- php7.0 <not-affected> (Affected code not present)
Fixed in PHP 7.4.11, 7.3.23, 7.2.34
PHP Bug:;a=commit;h=0216630ea2815a5789a24279a1211ac398d4de79

