openssl is vulnerable to improper access control. The vulnerability exists in evp_md_init_internal
and evp_cipher_init_internal
functions of digest.c
and evp_enc.c
respectively which allows an attacker to incorrectly pass NID_undef as this value in the call to EVP_CIPHER_meth_new().
git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=5485c56679d7c49b96e8fc8ca708b0b7e7c03c4b
github.com/openssl/openssl/commit/e00d9d59451874e8d9ae65c079dc6b07912d874d
github.com/openssl/openssl/pull/19300
psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0023
secdb.alpinelinux.org/edge/main.yaml
secdb.alpinelinux.org/v3.15/main.yaml
secdb.alpinelinux.org/v3.16/main.yaml
security.netapp.com/advisory/ntap-20221028-0014/
www.openssl.org/news/secadv/20221011.txt