Lucene search

K
osvGoogleOSV:RUSTSEC-2020-0015
HistoryApr 25, 2020 - 12:00 p.m.

Crash causing Denial of Service attack

2020-04-2512:00:00
Google
osv.dev
18

EPSS

0.081

Percentile

94.3%

Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3
handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the
“signature_algorithms_cert” TLS extension. The crash occurs if an invalid or unrecognised signature
algorithm is received from the peer. This could be exploited by a malicious peer in a Denial of
Service attack.