Lucene search

K
opensslOpenSSLOPENSSL:CVE-2023-0464
HistoryMar 21, 2023 - 12:00 a.m.

Vulnerability in OpenSSL - Excessive Resource Usage Verifying X.509 Policy Constraints

2023-03-2100:00:00
www.openssl-library.org
32
openssl
cve-2023-0464
security vulnerability
supported versions
software

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7.7

Confidence

High

EPSS

0.004

Percentile

72.6%

A security vulnerability has been identified in all supported versions

of OpenSSL related to the verification of X.509 certificate chains that include policy constraints. Attackers may be able to exploit this vulnerability by creating a malicious certificate chain that triggers exponential use of computational resources, leading to a denial-of-service (DoS) attack on affected systems.

Policy processing is disabled by default but can be enabled by passing the -policy argument to the command line utilities or by calling the X509_VERIFY_PARAM_set1_policies() function.

Found by David Benjamin (Google).
Fix developed by Dr Paul Dale.

Affected configurations

Vulners
Node
opensslopensslRange3.1.03.1.1
OR
opensslopensslRange3.0.03.0.9
OR
opensslopensslRange1.1.11.1.1u
OR
opensslopensslRange1.0.21.0.2zh
VendorProductVersionCPE
opensslopenssl*cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7.7

Confidence

High

EPSS

0.004

Percentile

72.6%