Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Debian 10 Buster DLA-3449-1 Moderate: OpenSSL DoS Threats

debian lts
Calendar Grey June 8, 2023
Dist Debian Esm H88
Enhance OpenSSL libraries to mitigate various security flaws encompassing denial of service threats and certificate policy complications.
Multiple vulnerabilities have been discovered in OpenSSL, a Secure Sockets Layer toolkit

Summary

CVE-2023-0464

David Benjamin reported a flaw related to the verification of
X.509 certificate chains that include policy constraints, which
may result in denial of service.

CVE-2023-0465

David Benjamin reported that invalid certificate policies in leaf
certificates are silently ignored. A malicious CA could take
advantage of this flaw to deliberately assert invalid certificate
policies in order to circumvent policy checking on the certificate
altogether.

CVE-2023-0466

David Benjamin discovered that the implementation of the
X509_VERIFY_PARAM_add0_policy() function does not enable the check
which allows certificates with invalid or incorrect policies to
pass the certificate verification (contrary to its documentation).

CVE-2023-2650

It was discovered that processing malformed ASN.1 object
identifiers or data may result in denial of service.

For Debian 10 buster, these problems have been fixed in version
1.1.1n-0+deb10u5.

Read the Full Advisory


Package: openssl
Version: 1.1.1n-0+deb10u5
CVE ID: CVE-2023-0464 CVE-2023-0465 CVE-2023-0466 CVE-2023-2650
Debian Bug: 1034720

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here