PT-2023-3466 · Mysql Server+10 · Mysql Server+10

Matt Caswell

+2

·

Published

2023-05-30

·

Updated

2026-04-27

·

CVE-2023-2650

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions OpenSSL versions prior to 3.0 OpenSSL versions 3.0 and newer MySQL Server versions 5.7.42 and earlier, 8.0.33 and earlier
Description The issue is related to the processing of specially crafted ASN.1 object identifiers, which can cause significant delays in applications using the OpenSSL library. This can lead to a Denial of Service (DoS) condition. The OBJ obj2txt() function is used to translate an ASN.1 OBJECT IDENTIFIER to its canonical numeric text form, and when dealing with very large sub-identifiers, the translation can take a very long time. The time complexity is O(n^2) with 'n' being the size of the sub-identifiers in bytes. The impact is relatively low on TLS due to the 100KiB limit on the peer's certificate chain. Applications that call OBJ obj2txt() directly with untrusted data are affected, with any version of OpenSSL.
Recommendations For OpenSSL versions prior to 3.0, consider upgrading to a newer version to mitigate the risk. For OpenSSL versions 3.0 and newer, ensure that the subsystems OCSP, PKCS7/SMIME, CMS, CMP/CRMF or TS have message size limits in place to prevent excessive delays. For MySQL Server versions 5.7.42 and earlier, 8.0.33 and earlier, upgrade to a newer version to address the vulnerability. As a temporary workaround, consider disabling the OBJ obj2txt() function or restricting its use with untrusted data until a patch is available.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Resource Exhaustion

Weakness Enumeration

Related Identifiers

ALSA-2023:3722
ALSA-2023:6330
ALT-PU-2023-1913
ALT-PU-2023-1937
ALT-PU-2023-1948
ALT-PU-2023-2039
ALT-PU-2023-2083
ALT-PU-2023-7324
ALT-PU-2023-7463
ALT-PU-2023-7647
ALT-PU-2023-7888
AZL-26984
AZL-27009
AZL-31144
AZL-34667
AZL-37674
BDU:2023-03652
CVE-2023-2650
DLA-3449-1
DSA-5417-1
JLSEC-2026-239
MGASA-2023-0195
OESA-2023-1354
OESA-2023-1355
OESA-2023-1356
OESA-2024-1222
OESA-2024-1223
OESA-2024-1224
OESA-2024-1225
OESA-2024-1226
OESA-2024-1227
OESA-2024-1238
OPENSUSE-SU-2024:12966-1
OPENSUSE-SU-2024:12969-1
OPENSUSE-SU-2024:12972-1
OPENSUSE-SU-2024:13029-1
OPENSUSE-SU-2024:13031-1
OPENSUSE-SU-2024:13032-1
OPENSUSE-SU-2024:13033-1
OPENSUSE-SU-2024:13038-1
OPENSUSE-SU-2024:14109-1
OPENSUSE-SU-2024:14434-1
OPENSUSE-SU-2025:15713-1
RHSA-2023:3722
RHSA-2023:6330
RHSA-2023:7622
RHSA-2023:7625
RHSA-2023_3722
RHSA-2023_6330
ROSA-SA-2024-2366
SUSE-SU-2023:2327-1
SUSE-SU-2023:2328-1
SUSE-SU-2023:2329-1
SUSE-SU-2023:2330-1
SUSE-SU-2023:2331-1
SUSE-SU-2023:2332-1
SUSE-SU-2023:2342-1
SUSE-SU-2023:2343-1
SUSE-SU-2023:2469-1
SUSE-SU-2023:2470-1
SUSE-SU-2023:2471-1
SUSE-SU-2023:2620-1
SUSE-SU-2023:29171-1
SUSE-SU-2023_2327-1
SUSE-SU-2023_2328-1
SUSE-SU-2023_2329-1
SUSE-SU-2023_2330-1
SUSE-SU-2023_2331-1
SUSE-SU-2023_2332-1
SUSE-SU-2023_2342-1
SUSE-SU-2023_2343-1
SUSE-SU-2023_2469-1
SUSE-SU-2023_2471-1
SUSE-SU-2023_29171-1
USN-6119-1
USN-6188-1
USN-6672-1
USN-7894-1
USN-7894-2

Affected Products

Alt Linux
Almalinux
Astra Linux
Ibm Aix
Linuxmint
Mysql Server
Openssl
Red Hat
Red Os
Suse
Ubuntu