RUSTSEC-2021-0055
Dashboard / Vulnerabilities / RUSTSEC-2021-0055
RUSTSEC-2021-0055
Summary: NULL pointer deref in signature_algorithms processing
Details: An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer dereference will result, leading to a crash and a denial of service attack. A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which is the default configuration). OpenSSL TLS clients are not impacted by this issue.
References: https://crates.io/crates/openssl-src, https://rustsec.org/advisories/RUSTSEC-2021-0055.html, https://www.openssl.org/news/secadv/20210325.txt
Affected packages
Package
Name: openssl-src
Purl: pkg:cargo/openssl-src
Affected ranges
Type: SEMVER
Events:
