CVE-2023-0286

Aliases:GHSA-x4qr-2fvf-3mr5RUSTSEC-2023-0006PYSEC-2026-800ALPINE-CVE-2023-0286RHSA-2023:1335RHSA-2023:1437RHSA-2023:1438RHSA-2023:1439RHSA-2023:1440RHSA-2023:1441RHSA-2023:2022RHSA-2023:4124RHSA-2023:4252RHSA-2024:5136RHSA-2025:7733RHSA-2025:7895RHSA-2025:7937DEBIAN-CVE-2023-0286CGA-h8wh-4jfx-p3cpCGA-jx2x-pfm7-h2cqCGA-m6hm-6vvr-h562CGA-mgv6-267q-63wqCGA-p5cv-98wp-p27pCGA-8vch-phmm-47mgCGA-hm5g-6q4r-2fqjCGA-vmrm-wv7f-ppgq
Advisory lineage Upstream: 0 Downstream: 60
Modified
Published: 08 Feb 2023, 19:01
Last modified:04 Nov 2025, 19:14

Vulnerability Summary

Overall Risk (default)
medium
42/100
CVSS Score
7.4 HIGH
v3.1 (cve.org)
EPSS Score
59.5% CRITICAL
60% probability -28.85%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

08 Feb 2023, 19:01
Published
Vulnerability first disclosed
04 Nov 2025, 19:14
Last Modified
Vulnerability information updated

Description

There is a type confusion vulnerability relating to X.400 address processing inside an X.509 GeneralName. X.400 addresses were parsed as an ASN1_STRING but the public structure definition for GENERAL_NAME incorrectly specified the type of the x400Address field as ASN1_TYPE. This field is subsequently interpreted by the OpenSSL function GENERAL_NAME_cmp as an ASN1_TYPE rather than an ASN1_STRING. When CRL checking is enabled (i.e. the application sets the X509_V_FLAG_CRL_CHECK flag), this vulnerability may allow an attacker to pass arbitrary pointers to a memcmp call, enabling them to read memory contents or enact a denial of service. In most cases, the attack requires the attacker to provide both the certificate chain and CRL, neither of which need to have a valid signature. If the attacker only controls one of these inputs, the other input must already contain an X.400 address as a CRL distribution point, which is uncommon. As such, this vulnerability is most likely to only affect applications which have implemented their own functionality for retrieving CRLs over a network.

CVSS Metrics

  • v3.1HIGHScore: 7.4CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H

EPSS Trends

Current EPSS score: 59.50% Percentile: 99%

Techniques & Countermeasures

  • CWE-843Access of Resource Using Incompatible Type ('Type Confusion')

    The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

Affected Systems

  • alpineopenssl

    ≥ 1.0.2, < 1.1.1t-r0 | ≥ 1.0.2, < 1.1.1t-r0 | ≥ 1.0.2, < 1.1.1t-r0 | ≥ 1.0.2, < 3.0.8-r0 | ≥ 1.0.2, < 3.0.8-r0 | ≥ 1.0.2, < 3.0.8-r0 | ≥ 1.0.2, < 3.0.8-r0 | ≥ 1.0.2, < 3.0.8-r0 | ≥ 1.0.2, < 3.0.8-r0 | ≥ 1.0.2, < 3.0.8-r0 | ≥ 1.0.2, < 3.0.8-r0

  • alpineopenssl3

    < 3.0.8-r0 | < 3.0.8-r0

  • chainguardmitmproxy

    < 12.2.1-r0

  • chainguardopenssl

    < 3.1.0-r0

  • chainguardopenssl-provider-fips

    < 3.0.8-r0

  • chainguardruby-3.1

    < 0

  • wolfimitmproxy

    < 12.2.1-r0

  • wolfiopenssl

    < 3.1.0-r0

  • wolfiruby-3.1

    < 0

  • Crates.Ioopenssl-src

    < 111.25.0 | ≥ 300.0.0, < 300.0.12

  • debianopenssl

    < 1.1.1n-0+deb11u4 | < 3.0.8-1 | < 3.0.8-1 | < 3.0.8-1

  • opensslopenssl

    ≥ 1.0.2, < 1.0.2zg | ≥ 1.1.1, < 1.1.1t | ≥ 3.0.0, < 3.0.8

  • PyPIcryptography

    ≥ 0.8.1, < 39.0.1

  • redhatcompat-openssl10

    < 1:1.0.2o-4.el8_10.1

  • redhatcompat-openssl10-debuginfo

    < 1:1.0.2o-4.el8_10.1

  • redhatcompat-openssl10-debugsource

    < 1:1.0.2o-4.el8_10.1

  • redhatcompat-openssl11

    < 1:1.1.1k-5.el9_4.1 | < 1:1.1.1k-5.el9_6.1

  • redhatcompat-openssl11-debuginfo

    < 1:1.1.1k-5.el9_4.1 | < 1:1.1.1k-5.el9_6.1

  • redhatcompat-openssl11-debugsource

    < 1:1.1.1k-5.el9_4.1 | < 1:1.1.1k-5.el9_6.1

  • redhatedk2

    < 0:20220126gitbb1bba3d77-3.el9_0.2 | < 0:20190829git37eef91017ad-9.el8_2.2 | < 0:20200602gitca407c7246bf-4.el8_4.3

  • redhatedk2-aarch64

    < 0:20220126gitbb1bba3d77-3.el9_0.2 | < 0:20200602gitca407c7246bf-4.el8_4.3

  • redhatedk2-ovmf

    < 0:20220126gitbb1bba3d77-3.el9_0.2 | < 0:20190829git37eef91017ad-9.el8_2.2 | < 0:20200602gitca407c7246bf-4.el8_4.3

  • redhatopenssl

    < 1:1.0.2k-26.el7_9 | < 1:1.0.2k-26.el7_9 | < 1:1.0.2k-26.el7_9 | < 1:1.1.1c-6.el8_1 | < 0:1.0.1e-61.el6_10 | < 1:1.1.1c-21.el8_2 | < 1:1.1.1g-18.el8_4 | < 1:1.1.1k-8.el8_6 | < 1:1.0.2k-21.el7_7.1

  • redhatopenssl-debuginfo

    < 1:1.0.2k-26.el7_9 | < 1:1.0.2k-26.el7_9 | < 1:1.0.2k-26.el7_9 | < 1:1.0.2k-26.el7_9 | < 1:1.1.1c-6.el8_1 | < 0:1.0.1e-61.el6_10 | < 1:1.1.1c-21.el8_2 | < 1:1.1.1g-18.el8_4 | < 1:1.1.1k-8.el8_6 | < 1:1.0.2k-21.el7_7.1

  • redhatopenssl-debugsource

    < 1:1.1.1c-6.el8_1 | < 1:1.1.1c-21.el8_2 | < 1:1.1.1g-18.el8_4 | < 1:1.1.1k-8.el8_6

  • redhatopenssl-devel

    < 1:1.0.2k-26.el7_9 | < 1:1.0.2k-26.el7_9 | < 1:1.0.2k-26.el7_9 | < 1:1.0.2k-26.el7_9 | < 1:1.1.1c-6.el8_1 | < 0:1.0.1e-61.el6_10 | < 1:1.1.1c-21.el8_2 | < 1:1.1.1g-18.el8_4 | < 1:1.1.1k-8.el8_6 | < 1:1.0.2k-21.el7_7.1

  • redhatopenssl-libs

    < 1:1.0.2k-26.el7_9 | < 1:1.0.2k-26.el7_9 | < 1:1.0.2k-26.el7_9 | < 1:1.1.1c-6.el8_1 | < 1:1.1.1c-21.el8_2 | < 1:1.1.1g-18.el8_4 | < 1:1.1.1k-8.el8_6 | < 1:1.0.2k-21.el7_7.1

  • redhatopenssl-libs-debuginfo

    < 1:1.1.1c-6.el8_1 | < 1:1.1.1c-21.el8_2 | < 1:1.1.1g-18.el8_4 | < 1:1.1.1k-8.el8_6

  • redhatopenssl-perl

    < 1:1.0.2k-26.el7_9 | < 1:1.0.2k-26.el7_9 | < 1:1.0.2k-26.el7_9 | < 1:1.0.2k-26.el7_9 | < 1:1.1.1c-6.el8_1 | < 0:1.0.1e-61.el6_10 | < 1:1.1.1c-21.el8_2 | < 1:1.1.1g-18.el8_4 | < 1:1.1.1k-8.el8_6 | < 1:1.0.2k-21.el7_7.1

  • redhatopenssl-static

    < 1:1.0.2k-26.el7_9 | < 1:1.0.2k-26.el7_9 | < 1:1.0.2k-26.el7_9 | < 1:1.0.2k-26.el7_9 | < 0:1.0.1e-61.el6_10 | < 1:1.0.2k-21.el7_7.1

  • stormshieldstormshield_management_center

    < 3.3.3

  • stormshieldstormshield network security

    ≥ 2.7.0, < 2.7.11 | ≥ 2.8.0, < 3.7.34 | ≥ 3.8.0, < 3.11.22 | ≥ 4.0.0, < 4.3.16 | ≥ 4.4.0, < 4.6.3

References (49)