7.5

CVE-2020-1967

Exploit

Segmentation fault in SSL_check_chain

Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signature_algorithms_cert" TLS extension. The crash occurs if an invalid or unrecognised signature algorithm is received from the peer. This could be exploited by a malicious peer in a Denial of Service attack. OpenSSL version 1.1.1d, 1.1.1e, and 1.1.1f are affected by this issue. This issue did not affect OpenSSL versions prior to 1.1.1d. Fixed in OpenSSL 1.1.1g (Affected 1.1.1d-1.1.1f).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OpenSSL ≫ OpenSSL Version >= 1.1.1d <= 1.1.1f
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
Freebsd ≫ Freebsd Version 12.1 Update -
Fedoraproject ≫ Fedora Version 30
Fedoraproject ≫ Fedora Version 31
Fedoraproject ≫ Fedora Version 32
Oracle ≫ Application Server Version 12.1.3
Oracle ≫ HTTP Server Version 12.2.1.4.0
Oracle ≫ Mysql Version <= 5.6.48
Oracle ≫ Mysql Version >= 5.7.0 <= 5.7.30
Oracle ≫ Mysql Version >= 8.0.0 <= 8.0.20
Oracle ≫ Mysql Connectors Version <= 8.0.20
Oracle ≫ Mysql Enterprise Monitor Version <= 4.0.12
Oracle ≫ Mysql Enterprise Monitor Version >= 8.0.0 <= 8.0.20
Oracle ≫ Mysql Workbench Version <= 8.0.21
Netapp ≫ Active Iq Unified Manager SwPlatform windows Version >= 7.3
Netapp ≫ Active Iq Unified Manager SwPlatform vmware_vsphere Version >= 9.5
Netapp ≫ Oncommand Insight Version -
Netapp ≫ Smi-s Provider Version -
Netapp ≫ Snapcenter Version -
Opensuse ≫ Leap Version 15.1
Opensuse ≫ Leap Version 15.2
Jdedwards ≫ Enterpriseone Version < 9.2.5.0
Tenable ≫ Log Correlation Engine Version < 6.0.9
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 53.34% 0.988
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.

https://www.oracle.com/security-alerts/cpujan2021.html
Patch
Third Party Advisory
https://www.oracle.com//security-alerts/cpujul2021.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpuoct2021.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpujul2020.html
Third Party Advisory
https://www.oracle.com/security-alerts/cpuoct2020.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpuApr2021.html
Patch
Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DDHOAATPWJCXRNFMJ2SASDBBNU5RJONY/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EXDDAOWSAIEFQNBHWYE6PPYFV4QXGMCD/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XVEP3LAK4JSPRXFO4QF4GG2IVXADV3SO/
https://security.gentoo.org/glsa/202004-10
Third Party Advisory
https://www.tenable.com/security/tns-2020-03
Third Party Advisory
https://www.tenable.com/security/tns-2020-11
Third Party Advisory
https://www.tenable.com/security/tns-2021-10
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00004.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00011.html
Third Party Advisory
Mailing List
http://packetstormsecurity.com/files/157527/OpenSSL-signature_algorithms_cert-Denial-Of-Service.html
Third Party Advisory
VDB Entry
http://seclists.org/fulldisclosure/2020/May/5
Third Party Advisory
Mailing List
http://www.openwall.com/lists/oss-security/2020/04/22/2
Third Party Advisory
Mailing List
https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=eb563247aef3e83dda7679c43f9649270462e5b1
https://github.com/irsl/CVE-2020-1967
Third Party Advisory
Exploit
https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44440
Third Party Advisory
https://lists.apache.org/thread.html/r66ea9c436da150683432db5fbc8beb8ae01886c6459ac30c2cea7345%40%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/r94d6ac3f010a38fccf4f432b12180a13fa1cf303559bd805648c9064%40%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/r9a41e304992ce6aec6585a87842b4f2e692604f5c892c37e3b0587ee%40%3Cdev.tomcat.apache.org%3E
https://security.FreeBSD.org/advisories/FreeBSD-SA-20:11.openssl.asc
Patch
Third Party Advisory
https://security.netapp.com/advisory/ntap-20200424-0003/
Third Party Advisory
https://security.netapp.com/advisory/ntap-20200717-0004/
Third Party Advisory
https://www.debian.org/security/2020/dsa-4661
Third Party Advisory
https://www.openssl.org/news/secadv/20200421.txt
Vendor Advisory
https://www.synology.com/security/advisory/Synology_SA_20_05
Third Party Advisory
https://www.synology.com/security/advisory/Synology_SA_20_05_OpenSSL
Third Party Advisory
https://www.tenable.com/security/tns-2020-04
Third Party Advisory