PT-2023-1352 · Openssl+12 · Openssl+12

David Benjamin

+1

·

Published

2022-11-29

·

Updated

2026-04-27

·

CVE-2023-0286

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenSSL (affected versions not specified)
Description There is a type confusion vulnerability relating to X.400 address processing inside an X.509 GeneralName. X.400 addresses were parsed as an ASN1 STRING but the public structure definition for GENERAL NAME incorrectly specified the type of the x400Address field as ASN1 TYPE. This field is subsequently interpreted by the OpenSSL function GENERAL NAME cmp as an ASN1 TYPE rather than an ASN1 STRING. When CRL checking is enabled (i.e. the application sets the X509 V FLAG CRL CHECK flag), this vulnerability may allow an attacker to pass arbitrary pointers to a memcmp call, enabling them to read memory contents or enact a denial of service. In most cases, the attack requires the attacker to provide both the certificate chain and CRL, neither of which need to have a valid signature. If the attacker only controls one of these inputs, the other input must already contain an X.400 address as a CRL distribution point, which is uncommon. As such, this vulnerability is most likely to only affect applications which have implemented their own functionality for retrieving CRLs over a network.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Use After Free

Type Confusion

Incorrect Type Conversion or Cast

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2023:0946
ALSA-2023:1405
ALSA-2023:2165
ALSA-2023:2932
ALSA-2025:7895
ALSA-2025:7937
ALT-PU-2023-1195
ALT-PU-2023-1221
ALT-PU-2023-1228
ALT-PU-2023-1299
ALT-PU-2023-1360
ALT-PU-2023-4398
ALT-PU-2023-5593
ALT-PU-2023-6187
ALT-PU-2023-6515
ALT-PU-2024-12487
ALT-PU-2024-14595
ALT-PU-2024-2511
ALT-PU-2024-6382
AZL-13564
AZL-13701
AZL-37614
AZL-37883
BDU:2023-00665
BDU:2023-00675
CESA-2023_1335
CESA-2023_1405
CESA-2023_2932
CESA-2025_7895
CVE-2023-0286
DLA-3325-1
DSA-5343-1
GHSA-X4QR-2FVF-3MR5
INFSA-2025_7895
INFSA-2025_7937
JLSEC-2026-234
MGASA-2023-0130
OESA-2023-1092
OESA-2023-1107
OESA-2023-1121
OESA-2023-1135
OESA-2023-1142
OPENSUSE-SU-2023_0305-1
OPENSUSE-SU-2023_0311-1
OPENSUSE-SU-2023_0312-1
OPENSUSE-SU-2024:12687-1
OPENSUSE-SU-2024:12688-1
OPENSUSE-SU-2024:12716-1
OPENSUSE-SU-2024:12787-1
OPENSUSE-SU-2024:12794-1
OPENSUSE-SU-2024:12976-1
OPENSUSE-SU-2024:13029-1
OPENSUSE-SU-2024:13031-1
OPENSUSE-SU-2024:13032-1
OPENSUSE-SU-2024:13033-1
OPENSUSE-SU-2024:13956-1
OPENSUSE-SU-2024:14109-1
OPENSUSE-SU-2024:14434-1
OPENSUSE-SU-2025:14821-1
OPENSUSE-SU-2025:15713-1
OPENSUSE-SU-2026:10348-1
RHSA-2023:0946
RHSA-2023:1199
RHSA-2023:1335
RHSA-2023:1405
RHSA-2023:1437
RHSA-2023:1438
RHSA-2023:1439
RHSA-2023:1440
RHSA-2023:1441
RHSA-2023:2022
RHSA-2023:2165
RHSA-2023:2932
RHSA-2023:3354
RHSA-2023:3420
RHSA-2023:4124
RHSA-2023:4128
RHSA-2023:4252
RHSA-2023:5209
RHSA-2023_0946
RHSA-2023_1335
RHSA-2023_1405
RHSA-2023_1438
RHSA-2023_2165
RHSA-2023_2932
RHSA-2024:5136
RHSA-2025:7733
RHSA-2025:7895
RHSA-2025:7937
RHSA-2025_7895
RHSA-2025_7937
RLSA-2023:0946
RLSA-2023:1405
ROSA-SA-2023-2152
RUSTSEC-2023-0006
SUSE-SU-2023:0305-1
SUSE-SU-2023:0305-2
SUSE-SU-2023:0306-1
SUSE-SU-2023:0307-1
SUSE-SU-2023:0308-1
SUSE-SU-2023:0309-1
SUSE-SU-2023:0310-1
SUSE-SU-2023:0311-1
SUSE-SU-2023:0312-1
SUSE-SU-2023:0482-1
SUSE-SU-2023:0684-1
USN-5844-1
USN-5845-1
USN-5845-2
USN-6564-1
USN-7894-1
USN-7894-2

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Freebsd
Ibm Aix
Linuxmint
Openssl
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu