发布时间: 2022年12月24日
修改时间: 2022年12月24日
If an X.509 certificate contains a malformed policy constraint and policy processing is enabled, then a write lock will be taken twice recursively. On some operating systems (most widely: Windows) this results in a denial of service when the affected process hangs. Policy processing being enabled on a publicly facing server is not considered to be a common setup. Policy processing is enabled by passing the `-policy argument to the command line utilities or by calling either `X509_VERIFY_PARAM_add0_policy() or `X509_VERIFY_PARAM_set1_policies() functions.
NVD | openEuler | |
---|---|---|
CVSS评分 | 7.5 | 0.0 |
Attack Vector | Network | |
Attack Complexity | Low | |
Privileges Required | None | |
User Interaction | None | |
Scope | Unchanged | |
Confidentiality | None | |
Integrity | None | |
Availability | High |
公告名 | 概要 | 发布时间 |
---|---|---|
KylinSec-SA-2022-2746 | If an X.509 certificate contains a malformed policy constraint and policy processing is enabled, then a write lock will be taken twice recursively. On some operating systems (most widely: Windows) this results in a denial of service when the affected process hangs. Policy processing being enabled on a publicly facing server is not considered to be a common setup. Policy processing is enabled by passing the `-policy argument to the command line utilities or by calling either `X509_VERIFY_PARAM_add0_policy() or `X509_VERIFY_PARAM_set1_policies() functions. | 2022年12月24日 |
产品 | 包 | 状态 |
---|---|---|
KY3.4-4A | openssl | Unaffected |
KY3.4-5A | openssl | Unaffected |
KY3.5.1 | openssl | Unaffected |