cbcvebase.
CVE-2020-1967
published 2020-04-21

CVE-2020-1967: Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signature_algorithms_cert" TLS extension. The crash occurs if an invalid or unrecognised signature algorithm is received from the peer. This could be exploited by a malicious peer in a Denial of Service attack. OpenSSL version 1.1.1d, 1.1.1e, and 1.1.1f are affected by this issue. This issue did not affect OpenSSL versions prior to 1.1.1d. Fixed in OpenSSL 1.1.1g (Affected 1.1.1d-1.1.1f).

Affected

38 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianopenssl< openssl 1.1.1g-1 (bookworm)openssl 1.1.1g-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
freebsdfreebsd
jdedwardsenterpriseone< 9.2.5.09.2.5.0
netappactive_iq_unified_manager>= 7.3
netappactive_iq_unified_manager>= 9.5
opensslopenssl
opensslopenssl>= 0 < 1.1.1g-11.1.1g-1
opensslopenssl>= 0 < 1.1.1g-11.1.1g-1
opensslopenssl>= 0 < 1.1.1g-11.1.1g-1
opensslopenssl>= 0 < 1.1.1g-11.1.1g-1
opensslopenssl1.1.1d – 1.1.1f
opensuseleap
opensuseleap
oracleapplication_server
oracleenterprise_manager_base_platform
oracleenterprise_manager_for_storage_management
oracleenterprise_manager_for_storage_management
oracleenterprise_manager_ops_center
oraclehttp_server
oraclejd_edwards_world_security

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH