cbcvebase.
CVE-2023-0216
published 2023-02-08

CVE-2023-0216: An invalid pointer dereference on read can be triggered when an application tries to load malformed PKCS7 data with the d2i_PKCS7(), d2i_PKCS7_bio() or…

PriorityP336high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.85%
76.7th percentile
An invalid pointer dereference on read can be triggered when an application tries to load malformed PKCS7 data with the d2i_PKCS7(), d2i_PKCS7_bio() or d2i_PKCS7_fp() functions. The result of the dereference is an application crash which could lead to a denial of service attack. The TLS implementation in OpenSSL does not call this function however third party applications might call these functions on untrusted data.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
debianopenssl< openssl 3.0.8-1 (bookworm)openssl 3.0.8-1 (bookworm)
opensslopenssl>= 0 < 3.0.8-r03.0.8-r0
opensslopenssl>= 0 < 3.0.8-r03.0.8-r0
opensslopenssl>= 0 < 3.0.8-r03.0.8-r0
opensslopenssl>= 0 < 3.0.8-r03.0.8-r0
opensslopenssl>= 0 < 3.0.8-r03.0.8-r0
opensslopenssl>= 0 < 3.0.8-r03.0.8-r0
opensslopenssl>= 0 < 3.0.8-r03.0.8-r0
opensslopenssl>= 0 < 3.0.8-13.0.8-1
opensslopenssl>= 0 < 3.0.8-13.0.8-1
opensslopenssl>= 0 < 3.0.8-13.0.8-1
opensslopenssl>= 0 < 1.1.1-1ubuntu2.1~18.04.211.1.1-1ubuntu2.1~18.04.21
opensslopenssl>= 0 < 1.1.1f-1ubuntu2.171.1.1f-1ubuntu2.17
opensslopenssl>= 0 < 3.0.2-0ubuntu1.83.0.2-0ubuntu1.8
opensslopenssl>= 3.0.0 < 3.0.83.0.8
opensslopenssl3.0.0 – 3.0.7
paloaltocortex_data
paloaltocortex_xdr
paloaltocortex_xpanse
paloaltocortex_xsoar
paloaltoglobalprotect
paloaltopan-os
paloaltoprisma_access
paloaltoprisma_cloud
paloaltoprisma_sd

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu4.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.