PT-2020-2778 · Mysql Server+5 · Mysql Server+5

Bernd Edlinger

·

Published

2020-04-21

·

Updated

2026-04-27

·

CVE-2020-1967

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenSSL versions 1.1.1d through 1.1.1f MySQL Server versions 5.6.48 and earlier, 5.7.30 and earlier, 8.0.20 and earlier
Description The issue is related to the incorrect handling of the "signature algorithms cert" TLS extension, which can cause a NULL pointer dereference and lead to a crash during or after a TLS 1.3 handshake. This could be exploited by a malicious peer in a Denial of Service attack. The crash occurs if an invalid or unrecognised signature algorithm is received from the peer.
Recommendations For OpenSSL versions 1.1.1d through 1.1.1f, update to OpenSSL 1.1.1g to fix the issue. For MySQL Server versions 5.6.48 and earlier, 5.7.30 and earlier, 8.0.20 and earlier, update to a version that includes the fix for this issue. As a temporary workaround, consider disabling the SSL check chain() function until a patch is available. Restrict access to the vulnerable module to minimize the risk of exploitation. Avoid using the signature algorithms cert TLS extension in the affected API endpoint until the issue is resolved.

Exploit

Fix

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_11035
ALSA-2025_16880
ALT-PU-2020-1879
ALT-PU-2020-1892
ALT-PU-2020-2640
ALT-PU-2021-1906
ALT-PU-2021-2380
ALT-PU-2021-2382
ALT-PU-2021-3668
ALT-PU-2021-3670
BDU:2020-02873
CVE-2020-1967
DSA-4661-1
FREEBSD-SA-20_11
GHSA-JQ65-29V4-4X35
JLSEC-2026-219
OPENSUSE-SU-2020:0933-1
OPENSUSE-SU-2020:0945-1
OPENSUSE-SU-2020_0933-1
OPENSUSE-SU-2020_0945-1
OPENSUSE-SU-2024:11127-1
OPENSUSE-SU-2024:11359-1
OPENSUSE-SU-2024:11360-1
RUSTSEC-2020-0015
SUSE-SU-2020:1058-1
SUSE-SU-2020:2041-1
SUSE-SU-2020_1058-1
SUSE-SU-2020_2041-1

Affected Products

Alt Linux
Freebsd
Huawei Vrp
Mysql Server
Openssl
Suse