PT-2026-4949 · Unknown+6 · Openssl 3.6+11
Norbert Pócs
+1
·
Published
2025-01-01
·
Updated
2026-03-15
·
CVE-2025-69419
CVSS v3.1
7.4
High
| AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
OpenSSL versions 1.1.1, 3.0, 3.3, 3.4, 3.5 and 3.6
Description
A flaw exists in the handling of maliciously crafted PKCS#12 files when using the
PKCS12 get friendlyname() API. Specifically, processing a PKCS#12 file with a BMPString (UTF-16BE) friendly name containing non-ASCII BMP code points can lead to a one-byte write before the allocated buffer. This out-of-bounds write can cause memory corruption, potentially resulting in a Denial of Service. The issue stems from an incorrect capacity calculation within the bmp to utf8() function during the UTF-16 to UTF-8 conversion process, specifically when handling BMP code points above U+07FF. The OPENSSL uni2utf8() function is involved in this conversion. The vulnerability is triggered when parsing attacker-controlled PKCS#12 files via the public PKCS12 get friendlyname() API. The FIPS modules in versions 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected.Recommendations
OpenSSL version 1.1.1: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
OpenSSL version 3.0: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
OpenSSL version 3.3: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
OpenSSL version 3.4: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
OpenSSL version 3.5: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
OpenSSL version 3.6: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Improper Check for Exceptional Conditions
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Freebsd
Ibm Aix
Linuxmint
Openssl 1.1.1
Openssl 3.0
Openssl 3.3
Openssl 3.4
Openssl 3.5
Openssl 3.6
Openssl
Rocky Linux
Ubuntu