PT-2023-8644 · Openssl+10 · Openssl+10

Bahaa Naamneh

+1

·

Published

2023-11-23

·

Updated

2026-05-12

·

CVE-2024-0727

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenSSL versions prior to 3.2 (excluding FIPS modules in 3.2, 3.1, and 3.0)
Description The issue arises from the improper handling of NULL fields in PKCS12 files, leading to a potential Denial of Service attack. Applications loading files in the PKCS12 format from untrusted sources might terminate abruptly due to a NULL pointer dereference. The affected OpenSSL APIs are: PKCS12 parse(), PKCS12 unpack p7data(), PKCS12 unpack p7encdata(), PKCS12 unpack authsafes(), and PKCS12 newpass().
Recommendations As a temporary workaround, consider disabling the use of PKCS12 parse(), PKCS12 unpack p7data(), PKCS12 unpack p7encdata(), PKCS12 unpack authsafes(), and PKCS12 newpass() functions until a patch is available. Restrict access to PKCS12 files from untrusted sources to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:2447
ALSA-2024:9088
ALT-PU-2024-16921
ALT-PU-2024-16925
ALT-PU-2024-17181
ALT-PU-2025-1127
ALT-PU-2025-1184
AZL-33935
AZL-33937
AZL-35049
AZL-35086
AZL-37767
AZL-39649
AZL-42721
AZL-42730
AZL-78540
BDU:2024-01337
CVE-2024-0727
DLA-3942-1
DLA-3942-2
GHSA-9V9H-CGJ8-H64P
INFSA-2024_2447
INFSA-2024_9088
JLSEC-2026-247
MGASA-2024-0020
MGASA-2024-0036
MGASA-2024-0281
OESA-2024-1147
OESA-2024-1223
OESA-2024-1224
OESA-2024-1225
OESA-2024-1226
OESA-2024-1238
OPENSUSE-SU-2024:13656-1
OPENSUSE-SU-2024:13662-1
OPENSUSE-SU-2024:13663-1
OPENSUSE-SU-2024_0518-1
OPENSUSE-SU-2024_0549-1
OPENSUSE-SU-2024_0815-1
OPENSUSE-SU-2024_0831-1
OPENSUSE-SU-2024_0833-1
RHSA-2024:2447
RHSA-2024:9088
RHSA-2024_2447
RHSA-2024_9088
RLSA-2024:9088
SUSE-SU-2024:0518-1
SUSE-SU-2024:0549-1
SUSE-SU-2024:0813-1
SUSE-SU-2024:0814-1
SUSE-SU-2024:0815-1
SUSE-SU-2024:0831-1
SUSE-SU-2024:0832-1
SUSE-SU-2024:0833-1
SUSE-SU-2024:0840-1
SUSE-SU-2024:0841-1
SUSE-SU-2024:0842-1
SUSE-SU-2024_0549-1
SUSE-SU-2024_0813-1
SUSE-SU-2024_0814-1
SUSE-SU-2024_0815-1
SUSE-SU-2024_0831-1
SUSE-SU-2024_0832-1
SUSE-SU-2024_0833-1
SUSE-SU-2024_0840-1
SUSE-SU-2024_0841-1
SUSE-SU-2024_0842-1
USN-6622-1
USN-6632-1
USN-6709-1
USN-7018-1
USN-7894-1
USN-7894-2

Affected Products

Alt Linux
Almalinux
Astra Linux
Ibm Aix
Linuxmint
Openssl
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu