It was discovered that the AES-CBC implementation in the PHP Secure Communications Library was susceptible to a padding oracle timing attack.
https://security-tracker.debian.org/tracker/DSA-6186-1
Continue reading...
https://security-tracker.debian.org/tracker/DSA-6186-1
Continue reading...

