Lucene search

K
rustsecRustsecRUSTSEC-2023-0011
HistoryFeb 07, 2023 - 12:00 p.m.

Invalid pointer dereference in `d2i_PKCS7` functions

2023-02-0712:00:00
rustsec.org
17
pointer dereference
pkcs7
openssl
denial of service
tls
third party
untrusted data
application crash

EPSS

0.002

Percentile

56.5%

An invalid pointer dereference on read can be triggered when an
application tries to load malformed PKCS7 data with the
d2i_PKCS7(), d2i_PKCS7_bio() or d2i_PKCS7_fp() functions.

The result of the dereference is an application crash which could
lead to a denial of service attack. The TLS implementation in OpenSSL
does not call this function however third party applications might
call these functions on untrusted data.