{"id":"UBUNTU-CVE-2023-49316","details":"In Math/BinaryField.php in phpseclib 3 before 3.0.34, excessively large degrees can lead to a denial of service.","modified":"2025-10-24T05:02:21Z","published":"2023-11-27T18:15:00Z","upstream":["CVE-2023-49316"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-49316"},{"type":"REPORT","url":"https://github.com/phpseclib/phpseclib/commit/964d78101a70305df33f442f5490f0adb3b7e77f"},{"type":"REPORT","url":"https://github.com/phpseclib/phpseclib/releases/tag/3.0.34"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2023-49316"}],"affected":[{"package":{"name":"php-phpseclib3","ecosystem":"Ubuntu:Pro:22.04:LTS","purl":"pkg:deb/ubuntu/php-phpseclib3@3.0.13-1ubuntu0.1~esm1?arch=source&distro=esm-apps/jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.0.9-1","3.0.10-1","3.0.12-2","3.0.13-1","3.0.13-1ubuntu0.1~esm1"],"ecosystem_specific":{"binaries":[{"binary_name":"php-phpseclib3","binary_version":"3.0.13-1ubuntu0.1~esm1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-49316.json"}},{"package":{"name":"php-phpseclib3","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/php-phpseclib3@3.0.37-1?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.0.21-2","3.0.33-1","3.0.34-1","3.0.35-1","3.0.37-1"],"ecosystem_specific":{"binaries":[{"binary_name":"php-phpseclib3","binary_version":"3.0.37-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-49316.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"medium"}]}