PT-2023-4567 · Openssl+9 · Openssl+9

David Benjamin

+1

·

Publicado

2023-03-28

·

Atualizado

2026-04-27

·

CVE-2023-0466

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenSSL (affected versions not specified)
Description The function X509 VERIFY PARAM add0 policy() is documented to implicitly enable the certificate policy check when doing certificate verification. However, the implementation of the function does not enable the check, which allows certificates with invalid or incorrect policies to pass the certificate verification. This could potentially allow a remote attacker to execute a "man-in-the-middle" attack. Certificate policy checks are disabled by default in OpenSSL and are not commonly used by applications.
Recommendations To resolve the issue, applications that require OpenSSL to perform certificate policy checks need to use X509 VERIFY PARAM set1 policies() or explicitly enable the policy check by calling X509 VERIFY PARAM set flags() with the X509 V FLAG POLICY CHECK flag argument. As a temporary workaround, consider disabling the use of the X509 VERIFY PARAM add0 policy() function until a patch is available. Restrict access to the vulnerable X509 VERIFY PARAM add0 policy() function to minimize the risk of exploitation.

Correção

DoS

Improper Certificate Validation

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2023:3722
ALT-PU-2023-1804
ALT-PU-2023-1876
ALT-PU-2023-1888
ALT-PU-2023-1913
ALT-PU-2023-1929
ALT-PU-2023-1937
ALT-PU-2023-1948
ALT-PU-2023-2039
ALT-PU-2023-2083
AZL-25936
AZL-47700
BDU:2023-04973
CVE-2023-0466
DLA-3449-1
DSA-5417-1
JLSEC-2026-237
MGASA-2023-0130
OESA-2023-1207
OESA-2024-1238
OPENSUSE-SU-2024:12837-1
OPENSUSE-SU-2024:12842-1
OPENSUSE-SU-2024:12969-1
RHSA-2023:3722
RHSA-2023:7622
RHSA-2023:7625
RHSA-2023_3722
ROSA-SA-2024-2366
SUSE-SU-2023:1790-1
SUSE-SU-2023:1794-1
SUSE-SU-2023:1898-1
SUSE-SU-2023:1907-1
SUSE-SU-2023:1908-1
SUSE-SU-2023:1911-1
SUSE-SU-2023:1914-1
SUSE-SU-2023:1922-1
SUSE-SU-2023:1926-1
USN-6039-1
USN-7894-1
USN-7894-2

Produtos afetados

Alt Linux
Almalinux
Astra Linux
Ibm Aix
Linuxmint
Openssl
Red Hat
Red Os
Suse
Ubuntu