Lucene search

K
osvGoogleOSV:RUSTSEC-2021-0055
HistoryMay 01, 2021 - 12:00 p.m.

NULL pointer deref in signature_algorithms processing

2021-05-0112:00:00
Google
osv.dev
14

0.005 Low

EPSS

Percentile

76.4%

An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation
ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits
the signature_algorithms extension (where it was present in the initial
ClientHello), but includes a signature_algorithms_cert extension then a NULL
pointer dereference will result, leading to a crash and a denial of service
attack.

A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which
is the default configuration). OpenSSL TLS clients are not impacted by this
issue.

CPENameOperatorVersion
openssl-srclt111.15.0