CVE-2023-0216
Vulnerability Summary
Timeline
Description
An invalid pointer dereference on read can be triggered when an application tries to load malformed PKCS7 data with the d2i_PKCS7(), d2i_PKCS7_bio() or d2i_PKCS7_fp() functions. The result of the dereference is an application crash which could lead to a denial of service attack. The TLS implementation in OpenSSL does not call this function however third party applications might call these functions on untrusted data.
CVSS Metrics
- v3.1•HIGH•Score: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Trends
Current EPSS score: 1.85%• Percentile: 78%
Techniques & Countermeasures
- CWE-476•NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.
Affected Systems
- alpine•openssl
≥ 3.0.0, < 3.0.8-r0 | ≥ 3.0.0, < 3.0.8-r0 | ≥ 3.0.0, < 3.0.8-r0 | ≥ 3.0.0, < 3.0.8-r0 | ≥ 3.0.0, < 3.0.8-r0 | ≥ 3.0.0, < 3.0.8-r0 | ≥ 3.0.0, < 3.0.8-r0 | ≥ 3.0.0, < 3.0.8-r0
- alpine•openssl3
< 3.0.8-r0 | < 3.0.8-r0
- chainguard•openssl
< 3.1.0-r0
- chainguard•openssl-provider-fips
< 3.0.8-r0
- chainguard•ruby-3.1
< 0
- wolfi•openssl
< 3.1.0-r0
- wolfi•ruby-3.1
< 0
- Crates.Io•openssl-src
≥ 300.0.0, < 300.0.12
- debian•openssl
< 3.0.8-1 | < 3.0.8-1 | < 3.0.8-1
- openssl•openssl
≥ 3.0.0, < 3.0.8 | ≥ 3.0.0, ≤ 3.0.7
- stormshield•stormshield_management_center
< 3.3.3
References (10)
- https://www.openssl.org/news/secadv/20230207.txt
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=934a04f0e775309cadbef0aa6b9692e1b12a76c6
- https://security.gentoo.org/glsa/202402-08
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0003
- https://nvd.nist.gov/vuln/detail/CVE-2023-0216
- https://rustsec.org/advisories/RUSTSEC-2023-0011.html
- https://crates.io/crates/openssl-src
- https://security.alpinelinux.org/vuln/CVE-2023-0216
- https://security-tracker.debian.org/tracker/CVE-2023-0216
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/0xxx/CVE-2023-0216.json