---
id: CVE-2020-1967
title: >-
  Server or client applications that call the SSL_check_chain() function during
  or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a
  result of incorrect handling of the "signature_algorithms_cert" TLS extension
summary: >-
  Server or client applications that call the SSL_check_chain() function during
  or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a
  result of incorrect handling of the "signature_algorithms_cert" TLS extension.
  Th…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-476
vendor: openssl
product: openssl
affected:
  - 'openssl >= 1.1.1d, <= 1.1.1f'
  - debian_linux = 9.0
  - debian_linux = 10.0
  - freebsd = 12.1
  - fedora = 30
  - fedora = 31
  - fedora = 32
  - application_server = 12.1.3
  - enterprise_manager_base_platform = 13.4.0.0
  - enterprise_manager_for_storage_management = 13.3.0.0
  - enterprise_manager_for_storage_management = 13.4.0.0
  - enterprise_manager_ops_center = 12.4.0
  - http_server = 12.2.1.4.0
  - jd_edwards_world_security = a9.4
  - mysql <= 5.6.48
  - 'mysql >= 5.7.0, <= 5.7.30'
  - 'mysql >= 8.0.0, <= 8.0.20'
  - mysql_connectors <= 8.0.20
  - mysql_enterprise_monitor <= 4.0.12
  - 'mysql_enterprise_monitor >= 8.0.0, <= 8.0.20'
  - mysql_workbench <= 8.0.21
  - peoplesoft_enterprise_peopletools = 8.56
  - peoplesoft_enterprise_peopletools = 8.57
  - peoplesoft_enterprise_peopletools = 8.58
  - peoplesoft_enterprise_peopletools = 8.59
  - active_iq_unified_manager >= 7.3
  - active_iq_unified_manager >= 9.5
  - e-series_performance_analyzer
  - oncommand_insight
  - oncommand_workflow_automation
  - smi-s_provider
  - snapcenter
  - steelstore_cloud_integrated_storage
  - fabric_operating_system
  - leap = 15.1
  - leap = 15.2
  - enterpriseone < 9.2.5.0
  - log_correlation_engine < 6.0.9
patched:
  - enterpriseone 9.2.5.0
  - log_correlation_engine 6.0.9
published: '2020-04-21'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T21:17:24.923'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-1967'
references:
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00004.html'
    label: openssl-security@openssl.org
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00011.html'
    label: openssl-security@openssl.org
  - url: >-
      http://packetstormsecurity.com/files/157527/OpenSSL-signature_algorithms_cert-Denial-Of-Service.html
    label: openssl-security@openssl.org
  - url: 'http://seclists.org/fulldisclosure/2020/May/5'
    label: openssl-security@openssl.org
  - url: 'http://www.openwall.com/lists/oss-security/2020/04/22/2'
    label: openssl-security@openssl.org
  - url: >-
      https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=eb563247aef3e83dda7679c43f9649270462e5b1
    label: openssl-security@openssl.org
  - url: 'https://github.com/irsl/CVE-2020-1967'
    label: openssl-security@openssl.org
  - url: 'https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44440'
    label: openssl-security@openssl.org
  - url: >-
      https://lists.apache.org/thread.html/r66ea9c436da150683432db5fbc8beb8ae01886c6459ac30c2cea7345%40%3Cdev.tomcat.apache.org%3E
    label: openssl-security@openssl.org
  - url: >-
      https://lists.apache.org/thread.html/r94d6ac3f010a38fccf4f432b12180a13fa1cf303559bd805648c9064%40%3Cdev.tomcat.apache.org%3E
    label: openssl-security@openssl.org
  - url: >-
      https://lists.apache.org/thread.html/r9a41e304992ce6aec6585a87842b4f2e692604f5c892c37e3b0587ee%40%3Cdev.tomcat.apache.org%3E
    label: openssl-security@openssl.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DDHOAATPWJCXRNFMJ2SASDBBNU5RJONY/
    label: openssl-security@openssl.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EXDDAOWSAIEFQNBHWYE6PPYFV4QXGMCD/
    label: openssl-security@openssl.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XVEP3LAK4JSPRXFO4QF4GG2IVXADV3SO/
    label: openssl-security@openssl.org
  - url: 'https://security.FreeBSD.org/advisories/FreeBSD-SA-20:11.openssl.asc'
    label: openssl-security@openssl.org
  - url: 'https://security.gentoo.org/glsa/202004-10'
    label: openssl-security@openssl.org
  - url: 'https://security.netapp.com/advisory/ntap-20200424-0003/'
    label: openssl-security@openssl.org
  - url: 'https://security.netapp.com/advisory/ntap-20200717-0004/'
    label: openssl-security@openssl.org
  - url: 'https://www.debian.org/security/2020/dsa-4661'
    label: openssl-security@openssl.org
  - url: 'https://www.openssl.org/news/secadv/20200421.txt'
    label: openssl-security@openssl.org
  - url: 'https://www.oracle.com//security-alerts/cpujul2021.html'
    label: openssl-security@openssl.org
  - url: 'https://www.oracle.com/security-alerts/cpuApr2021.html'
    label: openssl-security@openssl.org
  - url: 'https://www.oracle.com/security-alerts/cpujan2021.html'
    label: openssl-security@openssl.org
  - url: 'https://www.oracle.com/security-alerts/cpujul2020.html'
    label: openssl-security@openssl.org
  - url: 'https://www.oracle.com/security-alerts/cpuoct2020.html'
    label: openssl-security@openssl.org
  - url: 'https://www.oracle.com/security-alerts/cpuoct2021.html'
    label: openssl-security@openssl.org
  - url: 'https://www.synology.com/security/advisory/Synology_SA_20_05'
    label: openssl-security@openssl.org
  - url: 'https://www.synology.com/security/advisory/Synology_SA_20_05_OpenSSL'
    label: openssl-security@openssl.org
  - url: 'https://www.tenable.com/security/tns-2020-03'
    label: openssl-security@openssl.org
  - url: 'https://www.tenable.com/security/tns-2020-04'
    label: openssl-security@openssl.org
  - url: 'https://www.tenable.com/security/tns-2020-11'
    label: openssl-security@openssl.org
  - url: 'https://www.tenable.com/security/tns-2021-10'
    label: openssl-security@openssl.org
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00004.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00011.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      http://packetstormsecurity.com/files/157527/OpenSSL-signature_algorithms_cert-Denial-Of-Service.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://seclists.org/fulldisclosure/2020/May/5'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2020/04/22/2'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=eb563247aef3e83dda7679c43f9649270462e5b1
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://github.com/irsl/CVE-2020-1967'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44440'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r66ea9c436da150683432db5fbc8beb8ae01886c6459ac30c2cea7345%40%3Cdev.tomcat.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r94d6ac3f010a38fccf4f432b12180a13fa1cf303559bd805648c9064%40%3Cdev.tomcat.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r9a41e304992ce6aec6585a87842b4f2e692604f5c892c37e3b0587ee%40%3Cdev.tomcat.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DDHOAATPWJCXRNFMJ2SASDBBNU5RJONY/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EXDDAOWSAIEFQNBHWYE6PPYFV4QXGMCD/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XVEP3LAK4JSPRXFO4QF4GG2IVXADV3SO/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.FreeBSD.org/advisories/FreeBSD-SA-20:11.openssl.asc'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.gentoo.org/glsa/202004-10'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20200424-0003/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20200717-0004/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.debian.org/security/2020/dsa-4661'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.openssl.org/news/secadv/20200421.txt'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com//security-alerts/cpujul2021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuApr2021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujan2021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujul2020.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuoct2020.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuoct2021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.synology.com/security/advisory/Synology_SA_20_05'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.synology.com/security/advisory/Synology_SA_20_05_OpenSSL'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.tenable.com/security/tns-2020-03'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.tenable.com/security/tns-2020-04'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.tenable.com/security/tns-2020-11'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.tenable.com/security/tns-2021-10'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - exploit-available
epss: 0.53336
epssPercentile: 0.98961
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/irsl/CVE-2020-1967'
  checkedAt: '2026-10-08T22:12:29.992Z'
exploitAvailable: true
ingestedAt: '2026-10-08T22:11:53.714Z'
---

## Overview

Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signature_algorithms_cert" TLS extension. The crash occurs if an invalid or unrecognised signature algorithm is received from the peer. This could be exploited by a malicious peer in a Denial of Service attack. OpenSSL version 1.1.1d, 1.1.1e, and 1.1.1f are affected by this issue. This issue did not affect OpenSSL versions prior to 1.1.1d. Fixed in OpenSSL 1.1.1g (Affected 1.1.1d-1.1.1f).

## Affected

- `openssl >= 1.1.1d, <= 1.1.1f`
- `debian_linux = 9.0`
- `debian_linux = 10.0`
- `freebsd = 12.1`
- `fedora = 30`
- `fedora = 31`
- `fedora = 32`
- `application_server = 12.1.3`
- `enterprise_manager_base_platform = 13.4.0.0`
- `enterprise_manager_for_storage_management = 13.3.0.0`
- `enterprise_manager_for_storage_management = 13.4.0.0`
- `enterprise_manager_ops_center = 12.4.0`
- `http_server = 12.2.1.4.0`
- `jd_edwards_world_security = a9.4`
- `mysql <= 5.6.48`
- `mysql >= 5.7.0, <= 5.7.30`
- `mysql >= 8.0.0, <= 8.0.20`
- `mysql_connectors <= 8.0.20`
- `mysql_enterprise_monitor <= 4.0.12`
- `mysql_enterprise_monitor >= 8.0.0, <= 8.0.20`
- `mysql_workbench <= 8.0.21`
- `peoplesoft_enterprise_peopletools = 8.56`
- `peoplesoft_enterprise_peopletools = 8.57`
- `peoplesoft_enterprise_peopletools = 8.58`
- `peoplesoft_enterprise_peopletools = 8.59`
- `active_iq_unified_manager >= 7.3`
- `active_iq_unified_manager >= 9.5`
- `e-series_performance_analyzer`
- `oncommand_insight`
- `oncommand_workflow_automation`
- `smi-s_provider`
- `snapcenter`
- `steelstore_cloud_integrated_storage`
- `fabric_operating_system`
- `leap = 15.1`
- `leap = 15.2`
- `enterpriseone < 9.2.5.0`
- `log_correlation_engine < 6.0.9`

## Remediation

Upgrade past the affected range:

- `enterpriseone 9.2.5.0`
- `log_correlation_engine 6.0.9`
