Lucene search

K
osvGoogleOSV:GO-2022-0434
HistoryMay 23, 2022 - 9:59 p.m.

Panic during certificate parsing on Darwin in crypto/x509

2022-05-2321:59:00
Google
osv.dev
10
certificate parsing
darwin
tls
rfc 5280
crypto/tls
net/http
macos

AI Score

7.4

Confidence

High

EPSS

0.003

Percentile

66.0%

Verifying certificate chains containing certificates which are not compliant with RFC 5280 causes Certificate.Verify to panic on macOS.

These chains can be delivered through TLS and can cause a crypto/tls or net/http client to crash.