CVE-2020-1967High· 7.5▾ MidnightPoC availableServer or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signature_algorithms_cert" TLS extension. Th…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 41.3 · likelihood 10.7 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
53%
1 GitHub repo (last check)
Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signature_algorithms_cert" TLS extension. The crash occurs if an invalid or unrecognised signature algorithm is received from the peer. This could be exploited by a malicious peer in a Denial of Service attack. OpenSSL version 1.1.1d, 1.1.1e, and 1.1.1f are affected by this issue. This issue did not affect OpenSSL versions prior to 1.1.1d. Fixed in OpenSSL 1.1.1g (Affected 1.1.1d-1.1.1f).
openssl >= 1.1.1d, <= 1.1.1fdebian_linux = 9.0debian_linux = 10.0freebsd = 12.1fedora = 30fedora = 31fedora = 32application_server = 12.1.3enterprise_manager_base_platform = 13.4.0.0enterprise_manager_for_storage_management = 13.3.0.0enterprise_manager_for_storage_management = 13.4.0.0enterprise_manager_ops_center = 12.4.0http_server = 12.2.1.4.0jd_edwards_world_security = a9.4mysql <= 5.6.48mysql >= 5.7.0, <= 5.7.30mysql >= 8.0.0, <= 8.0.20mysql_connectors <= 8.0.20mysql_enterprise_monitor <= 4.0.12mysql_enterprise_monitor >= 8.0.0, <= 8.0.20mysql_workbench <= 8.0.21peoplesoft_enterprise_peopletools = 8.56peoplesoft_enterprise_peopletools = 8.57peoplesoft_enterprise_peopletools = 8.58peoplesoft_enterprise_peopletools = 8.59active_iq_unified_manager >= 7.3active_iq_unified_manager >= 9.5e-series_performance_analyzeroncommand_insightoncommand_workflow_automationsmi-s_providersnapcentersteelstore_cloud_integrated_storagefabric_operating_systemleap = 15.1leap = 15.2enterpriseone < 9.2.5.0log_correlation_engine < 6.0.9Upgrade past the affected range:
enterpriseone 9.2.5.0log_correlation_engine 6.0.9Connected by shared product, vendor, weakness, or advisory.
CVE-2021-3449Medium· 5.9An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client
CVE-2021-3450High· 7.4The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain
CVE-2019-1551Medium· 5.3There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli
CVE-2019-1563Low· 3.7In situations where an attacker receives automated notification of the success or failure of a decryption attempt an attacker, after sending a very large number of messages to be decrypted, can recover a CMS/PKCS7 transported encryption …
CVE-2018-0732High· 7.5During key agreement in a TLS handshake using a DH(E) based ciphersuite a malicious server can send a very large prime value to the client
CVE-2021-3711Critical· 9.8In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt()