cbcvebase.
CVE-2023-6237
published 2024-04-25

CVE-2023-6237: Issue summary: Checking excessively long invalid RSA public keys may take a long time. Impact summary: Applications that use the function…

PriorityP430medium5.9CVSS 3.1
AVNACHPRNUINSUCNINAH
EPSS
2.30%
81.5th percentile
Issue summary: Checking excessively long invalid RSA public keys may take a long time. Impact summary: Applications that use the function EVP_PKEY_public_check() to check RSA public keys may experience long delays. Where the key that is being checked has been obtained from an untrusted source this may lead to a Denial of Service. When function EVP_PKEY_public_check() is called on RSA public keys, a computation is done to confirm that the RSA modulus, n, is composite. For valid RSA keys, n is a product of two or more large primes and this computation completes quickly. However, if n is an overly large prime, then this computation would take a long time. An application that calls EVP_PKEY_public_check() and supplies an RSA key obtained from an untrusted source could be vulnerable to a Denial of Service attack. The function EVP_PKEY_public_check() is not called from other OpenSSL functions however it is called from the OpenSSL pkey command line application. For that reason that application is also vulnerable if used with the '-pubin' and '-check' options on untrusted data. The OpenSSL SSL/TLS implementation is not affected by this issue. The OpenSSL 3.0 and 3.1 FIPS providers are affected by this issue.

Affected

41 ranges· showing 25
VendorProductVersion rangeFixed in
debianopenssl< openssl 3.0.13-1~deb12u1 (bookworm)openssl 3.0.13-1~deb12u1 (bookworm)
haxxcurl>= 0 < 7.81.0-1ubuntu1.137.81.0-1ubuntu1.13
haxxcurl>= 0 < 7.35.0-1ubuntu2.20+esm167.35.0-1ubuntu2.20+esm16
haxxcurl>= 0 < 7.47.0-1ubuntu2.19+esm97.47.0-1ubuntu2.19+esm9
haxxcurl>= 0 < 7.58.0-2ubuntu3.24+esm17.58.0-2ubuntu3.24+esm1
msrcazl3_cloud-hypervisor-cvm_38.0.72-2_on_azure_linux_3.0
msrcazl3_cloud-hypervisor-cvm_38.0.72.2-1_on_azure_linux_3.0
msrcazl3_nodejs_20.10.0-2_on_azure_linux_3.0
msrcazl3_nodejs_20.14.0-1_on_azure_linux_3.0
msrcazl3_openssl_3.1.4-9_on_azure_linux_3.0
msrcazl3_openssl_3.3.0-1_on_azure_linux_3.0
msrcazl3_qemu_8.2.0-16_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl2_cloud-hypervisor-cvm_38.0.72-1_on_cbl_mariner_2.0
msrccbl2_cloud-hypervisor-cvm_38.0.72.2-1_on_cbl_mariner_2.0
msrccbl2_hvloader_1.0.1-5_on_cbl_mariner_2.0
msrccbl2_hvloader_1.0.1-6_on_cbl_mariner_2.0
msrccbl2_nodejs18_18.18.2-7_on_cbl_mariner_2.0
msrccbl2_nodejs18_18.20.2-1_on_cbl_mariner_2.0
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
opensslopenssl>= 0 < 3.0.12-r33.0.12-r3
opensslopenssl>= 0 < 3.1.4-r43.1.4-r4
opensslopenssl>= 0 < 3.1.4-r43.1.4-r4

CVSS provenance

nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.4HIGH
vendor_ubuntu7.4HIGH
vendor_debian5.9MEDIUM
vendor_msrc5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.