PT-2023-3200 · Openssl+9 · Openssl+9

David Benjamin

+1

·

Published

2023-03-28

·

Updated

2026-04-27

·

CVE-2023-0465

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenSSL (affected versions not specified)
Description The issue is related to the handling of invalid certificate policies in leaf certificates by OpenSSL. When a non-default option is used for verifying certificates, applications may be vulnerable to an attack from a malicious Certificate Authority (CA) that could circumvent certain checks. Invalid certificate policies in leaf certificates are silently ignored, and other certificate policy checks are skipped for that certificate. A malicious CA could deliberately assert invalid certificate policies to circumvent policy checking on the certificate altogether. Policy processing is disabled by default but can be enabled by passing the -policy argument to the command line utilities or by calling the X509 VERIFY PARAM set1 policies() function.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2023:3722
ALT-PU-2023-1804
ALT-PU-2023-1876
ALT-PU-2023-1888
ALT-PU-2023-1913
ALT-PU-2023-1929
ALT-PU-2023-1937
ALT-PU-2023-1948
ALT-PU-2023-2039
ALT-PU-2023-2083
AZL-25937
AZL-27241
AZL-31145
AZL-34663
AZL-37716
BDU:2023-03312
CVE-2023-0465
DLA-3449-1
DSA-5417-1
JLSEC-2026-236
MGASA-2023-0130
OESA-2023-1207
OESA-2024-1134
OESA-2024-1135
OESA-2024-1136
OESA-2024-1137
OESA-2024-1138
OESA-2024-1168
OESA-2024-1222
OESA-2024-1223
OESA-2024-1224
OESA-2024-1225
OESA-2024-1226
OESA-2024-1227
OESA-2024-1238
OPENSUSE-SU-2024:12837-1
OPENSUSE-SU-2024:12842-1
OPENSUSE-SU-2024:12969-1
RHSA-2023:3722
RHSA-2023:7622
RHSA-2023:7625
RHSA-2023_3722
ROSA-SA-2024-2366
SUSE-SU-2023:1790-1
SUSE-SU-2023:1794-1
SUSE-SU-2023:1898-1
SUSE-SU-2023:1907-1
SUSE-SU-2023:1908-1
SUSE-SU-2023:1911-1
SUSE-SU-2023:1912-1
SUSE-SU-2023:1914-1
SUSE-SU-2023:1922-1
SUSE-SU-2023:1926-1
SUSE-SU-2023:1960-1
SUSE-SU-2023_1794-1
SUSE-SU-2023_1898-1
SUSE-SU-2023_1907-1
SUSE-SU-2023_1908-1
SUSE-SU-2023_1911-1
SUSE-SU-2023_1912-1
SUSE-SU-2023_1914-1
SUSE-SU-2023_1922-1
SUSE-SU-2023_1926-1
SUSE-SU-2023_1960-1
USN-6039-1
USN-7894-1
USN-7894-2

Affected Products

Alt Linux
Almalinux
Astra Linux
Ibm Aix
Linuxmint
Openssl
Red Hat
Red Os
Suse
Ubuntu