RUSTSEC-2020-0015
Dashboard / Vulnerabilities / RUSTSEC-2020-0015
RUSTSEC-2020-0015
Published: 25 Apr 2020Last Modified: 15 Jul 2024
Aliases:
Summary: Crash causing Denial of Service attack
Details: Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signature_algorithms_cert" TLS extension. The crash occurs if an invalid or unrecognised signature algorithm is received from the peer. This could be exploited by a malicious peer in a Denial of Service attack.
References: https://crates.io/crates/openssl-src, https://rustsec.org/advisories/RUSTSEC-2020-0015.html, https://www.openssl.org/news/secadv/20200421.txt
Affected packages
Package
Name: openssl-src
Purl: pkg:cargo/openssl-src
Affected ranges
Type: SEMVER
Events:
Introduced- 111.6.0
Fixed -111.9.0
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
