Debian Security Updates Address phpseclib Vulnerabilities
Severity: Medium (Score: 45.9)
Sources: Linuxsecurity
Summary
Debian has released security updates for the phpseclib library across its oldstable and stable distributions. The updates address vulnerabilities identified as CVE-2023-52892, which affects multiple versions of phpseclib, including php-phpseclib3, php-phpseclib, and phpseclib. For the oldstable distribution (bookworm), the affected versions have been updated to 3.0.19-1+deb12u4, 2.0.42-1+deb12u3, and 1.0.20-1+deb12u3 respectively. The stable distribution (trixie) has received updates to versions 3.0.43-2+deb13u1, 2.0.48-3+deb13u1, and 1.0.23-6+deb13u1. Users are advised to upgrade their phpseclib packages to mitigate potential security risks. The vulnerabilities could expose systems to unauthorized access or data breaches if left unpatched. The updates were published on March 29, 2026, and are crucial for maintaining system integrity. Key Points: • Debian released security updates for phpseclib addressing CVE-2023-52892. • Affected versions include php-phpseclib3, php-phpseclib, and phpseclib. • Users are urged to upgrade to the latest patched versions to ensure security.
Key Entities
- CVE-2023-52892 (cve)
- Debian (company)
- Dsa-6186 (vulnerability)