cbcvebase.
CVE-2023-0217
published 2023-02-08

CVE-2023-0217: An invalid pointer dereference on read can be triggered when an application tries to check a malformed DSA public key by the EVP_PKEY_public_check() function…

PriorityP337high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.85%
76.7th percentile
An invalid pointer dereference on read can be triggered when an application tries to check a malformed DSA public key by the EVP_PKEY_public_check() function. This will most likely lead to an application crash. This function can be called on public keys supplied from untrusted sources which could allow an attacker to cause a denial of service attack. The TLS implementation in OpenSSL does not call this function but applications might call the function if there are additional security requirements imposed by standards such as FIPS 140-3.

Affected

25 ranges
VendorProductVersion rangeFixed in
debianopenssl< openssl 3.0.8-1 (bookworm)openssl 3.0.8-1 (bookworm)
opensslopenssl>= 0 < 3.0.8-r03.0.8-r0
opensslopenssl>= 0 < 3.0.8-r03.0.8-r0
opensslopenssl>= 0 < 3.0.8-r03.0.8-r0
opensslopenssl>= 0 < 3.0.8-r03.0.8-r0
opensslopenssl>= 0 < 3.0.8-r03.0.8-r0
opensslopenssl>= 0 < 3.0.8-r03.0.8-r0
opensslopenssl>= 0 < 3.0.8-r03.0.8-r0
opensslopenssl>= 0 < 3.0.8-13.0.8-1
opensslopenssl>= 0 < 3.0.8-13.0.8-1
opensslopenssl>= 0 < 3.0.8-13.0.8-1
opensslopenssl>= 0 < 1.1.1-1ubuntu2.1~18.04.211.1.1-1ubuntu2.1~18.04.21
opensslopenssl>= 0 < 1.1.1f-1ubuntu2.171.1.1f-1ubuntu2.17
opensslopenssl>= 0 < 3.0.2-0ubuntu1.83.0.2-0ubuntu1.8
opensslopenssl>= 3.0.0 < 3.0.83.0.8
opensslopenssl3.0.0 – 3.0.7
paloaltocortex_data
paloaltocortex_xdr
paloaltocortex_xpanse
paloaltocortex_xsoar
paloaltoglobalprotect
paloaltopan-os
paloaltoprisma_access
paloaltoprisma_cloud
paloaltoprisma_sd

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu4.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.