|
|
| |
| |
CERT-In Vulnerability Note
CIVN-2020-0444
NULL pointer dereference Vulnerability in OpenSSL
Original Issue Date:December 21, 2020
Severity Rating: MEDIUM
Software Affected
- OpenSSL versions 1.1.1 and 1.0.2
Overview
A NULL pointer dereference vulnerability has been found in Open SSL which may lead to a possible denial of service(DoS) attack on a server or client application running OpenSSL.
Description
This vulnerability is due to a NULL pointer de-reference error. A remote attacker can trigger denial of service conditions via the API functions viz TS_RESP_verify_response and TS_RESP_verify_token. An attacker could exploit this vulnerability by controlling both items being compared. For example if the attacker can trick a client or server into checking a malicious certificate against a malicious CRL then this may occur.
CERT-IN - Computer Emergency Response Team - Page Requested Currently Not available
CERT-IN - Computer Emergency Response Team - Page Requested Currently Not available
| | | |