7.5

CVE-2024-6119

Possible denial of service in X.509 name checks

Issue summary: Applications performing certificate name checks (e.g., TLS
clients checking server certificates) may attempt to read an invalid memory
address resulting in abnormal termination of the application process.

Impact summary: Abnormal termination of an application can a cause a denial of
service.

Applications performing certificate name checks (e.g., TLS clients checking
server certificates) may attempt to read an invalid memory address when
comparing the expected name with an `otherName` subject alternative name of an
X.509 certificate. This may result in an exception that terminates the
application program.

Note that basic certificate chain validation (signatures, dates, ...) is not
affected, the denial of service can occur only when the application also
specifies an expected DNS name, Email address or IP address.

TLS servers rarely solicit client certificates, and even when they do, they
generally don't perform a name check against a reference identifier (expected
identity), but rather extract the presented identity after checking the
certificate chain.  So TLS servers are generally not affected and the severity
of the issue is Moderate.

The FIPS modules in 3.3, 3.2, 3.1 and 3.0 are not affected by this issue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OpenSSL ≫ OpenSSL Version >= 3.0.0 < 3.0.15
OpenSSL ≫ OpenSSL Version >= 3.1.0 < 3.1.7
OpenSSL ≫ OpenSSL Version >= 3.2.0 < 3.2.3
OpenSSL ≫ OpenSSL Version >= 3.3.0 < 3.3.2
Netapp ≫ Active Iq Unified Manager Version - SwPlatform vmware_vsphere
Netapp ≫ Ontap 9 Version -
Netapp ≫ Ontap Tools Version 9 SwPlatform vmware_vsphere
Netapp ≫ H300s Firmware Version -
   Netapp ≫ H300s Version -
Netapp ≫ H500s Firmware Version -
   Netapp ≫ H500s Version -
Netapp ≫ H700s Firmware Version -
   Netapp ≫ H700s Version -
Netapp ≫ H410s Firmware Version -
   Netapp ≫ H410s Version -
Netapp ≫ H410c Firmware Version -
   Netapp ≫ H410c Version -
Netapp ≫ H610c Firmware Version -
   Netapp ≫ H610c Version -
Netapp ≫ H610s Firmware Version -
   Netapp ≫ H610s Version -
Netapp ≫ H615c Version -
   Netapp ≫ H615c Firmware Version -
Netapp ≫ Bootstrap Os Version -
   Netapp ≫ Hci Compute Node Version -
Netapp ≫ A250 Firmware Version -
   Netapp ≫ A250 Version -
Netapp ≫ 500f Firmware Version -
   Netapp ≫ 500f Version -
Netapp ≫ C250 Firmware Version -
   Netapp ≫ C250 Version -
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 66.58% 0.992
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA-ADP 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-843 Access of Resource Using Incompatible Type ('Type Confusion')

The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

https://cert-portal.siemens.com/productcert/html/ssa-769027.html
https://github.com/openssl/openssl/commit/05f360d9e849a1b277db628f1f13083a7f8dd04f
Patch
https://github.com/openssl/openssl/commit/06d1dc3fa96a2ba5a3e22735a033012aadc9f0d6
Patch
https://github.com/openssl/openssl/commit/621f3729831b05ee828a3203eddb621d014ff2b2
Patch
https://github.com/openssl/openssl/commit/7dfcee2cd2a63b2c64b9b4b0850be64cb695b0a0
Patch
https://openssl-library.org/news/secadv/20240903.txt
Vendor Advisory
http://www.openwall.com/lists/oss-security/2024/09/03/4
Mailing List
https://lists.freebsd.org/archives/freebsd-security/2024-September/000303.html
Mailing List
https://security.netapp.com/advisory/ntap-20240912-0001/
Third Party Advisory
https://cert-portal.siemens.com/productcert/html/ssa-082556.html
https://cert-portal.siemens.com/productcert/html/ssa-613116.html