​
DirectorySecurity Advisories
Sign In
Security Advisories

CGA-5rp8-x8jf-fpcq

Published

Last updated

https://images.chainguard.dev/security/CGA-5rp8-x8jf-fpcq
Package

openssl

Latest Update
Fixed
Fixed Version

3.1.0-r0

Aliases
  • CVE-2023-0216
  • GHSA-29xx-hcv2-c4cp

Severity

7.5

High

CVSS V3

Summary

openssl-src subject to Invalid pointer dereference in d2i_PKCS7 functions

Description

An invalid pointer dereference on read can be triggered when an application tries to load malformed PKCS7 data with the d2i_PKCS7(), d2i_PKCS7_bio() or d2i_PKCS7_fp() functions.

The result of the dereference is an application crash which could lead to a denial of service attack. The TLS implementation in OpenSSL does not call this function however third party applications might call these functions on untrusted data.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images