PT-2023-15779 · Openbsd+1 · Libressl+2
Ilya Shipitsin
·
Published
2022-11-05
·
Updated
2023-09-16
·
CVE-2022-48437
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
LibreSSL versions prior to 3.6.1
OpenBSD versions prior to 7.2 errata 001
Description
An issue was discovered in the x509/x509 verify.c file. The function x509 verify ctx add chain does not store errors that occur during leaf certificate verification, resulting in an incorrect error being returned. This behavior occurs when there is an installed verification callback that instructs the verifier to continue upon detecting an invalid certificate.
Recommendations
For LibreSSL versions prior to 3.6.1, update to version 3.6.1 or later to resolve the issue.
For OpenBSD versions prior to 7.2 errata 001, apply the 7.2 errata 001 patch to resolve the issue.
As a temporary workaround, consider disabling the installed verification callback that instructs the verifier to continue upon detecting an invalid certificate until a patch is available.
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Libressl
Openbsd