Lucene search

K
redhatcveRedhat.comRH:CVE-2022-3996
HistoryDec 14, 2022 - 11:04 a.m.

CVE-2022-3996

2022-12-1411:04:49
redhat.com
access.redhat.com
19
openssl
x.509 certificate
policy constraint
denial of service
windows
policy processing
publicly-facing server

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.001 Low

EPSS

Percentile

45.2%

A vulnerability was found in OpenSSL. This security flaw occurs if an X.509 certificate contains a malformed policy constraint and policy processing is enabled, then a write lock will be taken twice recursively. On some operating systems (most widely: Windows), this issue results in a denial of service when the affected process hangs. Policy processing enabled on a publicly-facing server is not considered a standard setup. Policy processing is enabled by passing the -policy' argument to the command line utilities or by calling either the X509_VERIFY_PARAM_add0_policy()’ or `X509_VERIFY_PARAM_set1_policies()’ functions.

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.001 Low

EPSS

Percentile

45.2%