• 公告ID (KylinSec-SA-2023-1061)

摘要:

An invalid pointer dereference on read can be triggered when an application tries to check a malformed DSA public key by the EVP_PKEY_public_check() function. This will most likely lead to an application crash. This function can be called on public keys supplied from untrusted sources which could allow an attacker to cause a denial of service attack. The TLS implementation in OpenSSL does not call this function but applications might call the function if there are additional security requirements imposed by standards such as FIPS 140-3.

安全等级: Low

公告ID: KylinSec-SA-2023-1061

发布日期: 2023年2月13日

关联CVE: CVE-2023-0217  

  • 详细介绍

1. 漏洞描述

   

An invalid pointer dereference on read can be triggered when an application tries to check a malformed DSA public key by the EVP_PKEY_public_check() function. This will most likely lead to an application crash. This function can be called on public keys supplied from untrusted sources which could allow an attacker to cause a denial of service attack. The TLS implementation in OpenSSL does not call this function but applications might call the function if there are additional security requirements imposed by standards such as FIPS 140-3.

2. 影响范围

cve名称 产品 组件 是否受影响
CVE-2023-0217 KY3.4-4A openssl Unaffected
CVE-2023-0217 KY3.4-5A openssl Unaffected
CVE-2023-0217 KY3.5.1 openssl Unaffected
CVE-2023-0217 KY3.5.2 openssl Unaffected

3. 影响组件

    无

4. 修复版本

    无

5. 修复方法

   无

6. 下载链接

    无
上一篇:KylinSec-SA-2023-1060 下一篇:KylinSec-SA-2023-1062