Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Debian 11: DSA-5417-1 Critical: OpenSSL Denial Of Service Issues

debian
Calendar Grey May 31, 2023
Debian Logo
Enhance OpenSSL on Debian to address several vulnerabilities impacting certificate validation and potential denial of service issues.
Multiple vulnerabilities have been discovered in OpenSSL, a Secure Sockets Layer toolkit

Summary

CVE-2023-0464

David Benjamin reported a flaw related to the verification of X.509
certificate chains that include policy constraints, which may result
in denial of service.

CVE-2023-0465

David Benjamin reported that invalid certificate policies in leaf
certificates are silently ignored. A malicious CA could take
advantage of this flaw to deliberately assert invalid certificate
policies in order to circumvent policy checking on the certificate
altogether.

CVE-2023-0466

David Benjamin discovered that the implementation of the
X509_VERIFY_PARAM_add0_policy() function does not enable the check
which allows certificates with invalid or incorrect policies to pass
the certificate verification (contrary to its documentation).

CVE-2023-2650

It was discovered that processing malformed ASN.1 object identifiers or data may result in denial of service.

For the stable distribution (bullseye), these problems have been fixed in
version 1.1.1n-0+deb11u5.

We recomm...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: openssl
CVE ID: CVE-2023-0464 CVE-2023-0465 CVE-2023-0466 CVE-2023-2650

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here