{"id":"CVE-2020-1967","title":"Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the \"signature_algorithms_cert\" TLS extension","summary":"Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the \"signature_algorithms_cert\" TLS extension. Th…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-476"],"vendor":"openssl","product":"openssl","affected":["openssl >= 1.1.1d, <= 1.1.1f","debian_linux = 9.0","debian_linux = 10.0","freebsd = 12.1","fedora = 30","fedora = 31","fedora = 32","application_server = 12.1.3","enterprise_manager_base_platform = 13.4.0.0","enterprise_manager_for_storage_management = 13.3.0.0","enterprise_manager_for_storage_management = 13.4.0.0","enterprise_manager_ops_center = 12.4.0","http_server = 12.2.1.4.0","jd_edwards_world_security = a9.4","mysql <= 5.6.48","mysql >= 5.7.0, <= 5.7.30","mysql >= 8.0.0, <= 8.0.20","mysql_connectors <= 8.0.20","mysql_enterprise_monitor <= 4.0.12","mysql_enterprise_monitor >= 8.0.0, <= 8.0.20","mysql_workbench <= 8.0.21","peoplesoft_enterprise_peopletools = 8.56","peoplesoft_enterprise_peopletools = 8.57","peoplesoft_enterprise_peopletools = 8.58","peoplesoft_enterprise_peopletools = 8.59","active_iq_unified_manager >= 7.3","active_iq_unified_manager >= 9.5","e-series_performance_analyzer","oncommand_insight","oncommand_workflow_automation","smi-s_provider","snapcenter","steelstore_cloud_integrated_storage","fabric_operating_system","leap = 15.1","leap = 15.2","enterpriseone < 9.2.5.0","log_correlation_engine < 6.0.9"],"patched":["enterpriseone 9.2.5.0","log_correlation_engine 6.0.9"],"published":"2020-04-21","updated":"2026-10-08","sourceUpdated":"2026-10-08T21:17:24.923","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2020-1967","references":[{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00004.html","label":"openssl-security@openssl.org"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00011.html","label":"openssl-security@openssl.org"},{"url":"http://packetstormsecurity.com/files/157527/OpenSSL-signature_algorithms_cert-Denial-Of-Service.html","label":"openssl-security@openssl.org"},{"url":"http://seclists.org/fulldisclosure/2020/May/5","label":"openssl-security@openssl.org"},{"url":"http://www.openwall.com/lists/oss-security/2020/04/22/2","label":"openssl-security@openssl.org"},{"url":"https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=eb563247aef3e83dda7679c43f9649270462e5b1","label":"openssl-security@openssl.org"},{"url":"https://github.com/irsl/CVE-2020-1967","label":"openssl-security@openssl.org"},{"url":"https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44440","label":"openssl-security@openssl.org"},{"url":"https://lists.apache.org/thread.html/r66ea9c436da150683432db5fbc8beb8ae01886c6459ac30c2cea7345%40%3Cdev.tomcat.apache.org%3E","label":"openssl-security@openssl.org"},{"url":"https://lists.apache.org/thread.html/r94d6ac3f010a38fccf4f432b12180a13fa1cf303559bd805648c9064%40%3Cdev.tomcat.apache.org%3E","label":"openssl-security@openssl.org"},{"url":"https://lists.apache.org/thread.html/r9a41e304992ce6aec6585a87842b4f2e692604f5c892c37e3b0587ee%40%3Cdev.tomcat.apache.org%3E","label":"openssl-security@openssl.org"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DDHOAATPWJCXRNFMJ2SASDBBNU5RJONY/","label":"openssl-security@openssl.org"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EXDDAOWSAIEFQNBHWYE6PPYFV4QXGMCD/","label":"openssl-security@openssl.org"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XVEP3LAK4JSPRXFO4QF4GG2IVXADV3SO/","label":"openssl-security@openssl.org"},{"url":"https://security.FreeBSD.org/advisories/FreeBSD-SA-20:11.openssl.asc","label":"openssl-security@openssl.org"},{"url":"https://security.gentoo.org/glsa/202004-10","label":"openssl-security@openssl.org"},{"url":"https://security.netapp.com/advisory/ntap-20200424-0003/","label":"openssl-security@openssl.org"},{"url":"https://security.netapp.com/advisory/ntap-20200717-0004/","label":"openssl-security@openssl.org"},{"url":"https://www.debian.org/security/2020/dsa-4661","label":"openssl-security@openssl.org"},{"url":"https://www.openssl.org/news/secadv/20200421.txt","label":"openssl-security@openssl.org"},{"url":"https://www.oracle.com//security-alerts/cpujul2021.html","label":"openssl-security@openssl.org"},{"url":"https://www.oracle.com/security-alerts/cpuApr2021.html","label":"openssl-security@openssl.org"},{"url":"https://www.oracle.com/security-alerts/cpujan2021.html","label":"openssl-security@openssl.org"},{"url":"https://www.oracle.com/security-alerts/cpujul2020.html","label":"openssl-security@openssl.org"},{"url":"https://www.oracle.com/security-alerts/cpuoct2020.html","label":"openssl-security@openssl.org"},{"url":"https://www.oracle.com/security-alerts/cpuoct2021.html","label":"openssl-security@openssl.org"},{"url":"https://www.synology.com/security/advisory/Synology_SA_20_05","label":"openssl-security@openssl.org"},{"url":"https://www.synology.com/security/advisory/Synology_SA_20_05_OpenSSL","label":"openssl-security@openssl.org"},{"url":"https://www.tenable.com/security/tns-2020-03","label":"openssl-security@openssl.org"},{"url":"https://www.tenable.com/security/tns-2020-04","label":"openssl-security@openssl.org"},{"url":"https://www.tenable.com/security/tns-2020-11","label":"openssl-security@openssl.org"},{"url":"https://www.tenable.com/security/tns-2021-10","label":"openssl-security@openssl.org"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00004.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00011.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://packetstormsecurity.com/files/157527/OpenSSL-signature_algorithms_cert-Denial-Of-Service.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://seclists.org/fulldisclosure/2020/May/5","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.openwall.com/lists/oss-security/2020/04/22/2","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=eb563247aef3e83dda7679c43f9649270462e5b1","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/irsl/CVE-2020-1967","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44440","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r66ea9c436da150683432db5fbc8beb8ae01886c6459ac30c2cea7345%40%3Cdev.tomcat.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r94d6ac3f010a38fccf4f432b12180a13fa1cf303559bd805648c9064%40%3Cdev.tomcat.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r9a41e304992ce6aec6585a87842b4f2e692604f5c892c37e3b0587ee%40%3Cdev.tomcat.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DDHOAATPWJCXRNFMJ2SASDBBNU5RJONY/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EXDDAOWSAIEFQNBHWYE6PPYFV4QXGMCD/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XVEP3LAK4JSPRXFO4QF4GG2IVXADV3SO/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.FreeBSD.org/advisories/FreeBSD-SA-20:11.openssl.asc","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.gentoo.org/glsa/202004-10","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20200424-0003/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20200717-0004/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.debian.org/security/2020/dsa-4661","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.openssl.org/news/secadv/20200421.txt","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com//security-alerts/cpujul2021.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuApr2021.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpujan2021.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpujul2020.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuoct2020.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuoct2021.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.synology.com/security/advisory/Synology_SA_20_05","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.synology.com/security/advisory/Synology_SA_20_05_OpenSSL","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.tenable.com/security/tns-2020-03","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.tenable.com/security/tns-2020-04","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.tenable.com/security/tns-2020-11","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.tenable.com/security/tns-2021-10","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","exploit-available"],"epss":0.53336,"epssPercentile":0.98961,"exploits":{"github":1,"githubRepos":["https://github.com/irsl/CVE-2020-1967"],"checkedAt":"2026-10-08T22:12:29.992Z"},"exploitAvailable":true,"ingestedAt":"2026-10-08T22:11:53.714Z","slug":"CVE-2020-1967","body":"## Overview\n\nServer or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the \"signature_algorithms_cert\" TLS extension. The crash occurs if an invalid or unrecognised signature algorithm is received from the peer. This could be exploited by a malicious peer in a Denial of Service attack. OpenSSL version 1.1.1d, 1.1.1e, and 1.1.1f are affected by this issue. This issue did not affect OpenSSL versions prior to 1.1.1d. Fixed in OpenSSL 1.1.1g (Affected 1.1.1d-1.1.1f).\n\n## Affected\n\n- `openssl >= 1.1.1d, <= 1.1.1f`\n- `debian_linux = 9.0`\n- `debian_linux = 10.0`\n- `freebsd = 12.1`\n- `fedora = 30`\n- `fedora = 31`\n- `fedora = 32`\n- `application_server = 12.1.3`\n- `enterprise_manager_base_platform = 13.4.0.0`\n- `enterprise_manager_for_storage_management = 13.3.0.0`\n- `enterprise_manager_for_storage_management = 13.4.0.0`\n- `enterprise_manager_ops_center = 12.4.0`\n- `http_server = 12.2.1.4.0`\n- `jd_edwards_world_security = a9.4`\n- `mysql <= 5.6.48`\n- `mysql >= 5.7.0, <= 5.7.30`\n- `mysql >= 8.0.0, <= 8.0.20`\n- `mysql_connectors <= 8.0.20`\n- `mysql_enterprise_monitor <= 4.0.12`\n- `mysql_enterprise_monitor >= 8.0.0, <= 8.0.20`\n- `mysql_workbench <= 8.0.21`\n- `peoplesoft_enterprise_peopletools = 8.56`\n- `peoplesoft_enterprise_peopletools = 8.57`\n- `peoplesoft_enterprise_peopletools = 8.58`\n- `peoplesoft_enterprise_peopletools = 8.59`\n- `active_iq_unified_manager >= 7.3`\n- `active_iq_unified_manager >= 9.5`\n- `e-series_performance_analyzer`\n- `oncommand_insight`\n- `oncommand_workflow_automation`\n- `smi-s_provider`\n- `snapcenter`\n- `steelstore_cloud_integrated_storage`\n- `fabric_operating_system`\n- `leap = 15.1`\n- `leap = 15.2`\n- `enterpriseone < 9.2.5.0`\n- `log_correlation_engine < 6.0.9`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `enterpriseone 9.2.5.0`\n- `log_correlation_engine 6.0.9`","depth":"midnight","depthScore":64,"depthScoreParts":{"impact":41.3,"likelihood":10.7,"exploitation":12,"ransomware":0},"changes":[]}