Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signature_algorithms_cert" TLS extension. The crash occurs if an invalid or unrecognised signature algorithm is received from the peer. This could be exploited by a malicious peer in a Denial of Service attack. OpenSSL version 1.1.1d, 1.1.1e, and 1.1.1f are affected by this issue. This issue did not affect OpenSSL versions prior to 1.1.1d. Fixed in OpenSSL 1.1.1g (Affected 1.1.1d-1.1.1f).
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00004.html
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00011.html
http://packetstormsecurity.com/files/157527/OpenSSL-signature_algorithms_cert-Denial-Of-Service.html
http://seclists.org/fulldisclosure/2020/May/5
http://www.openwall.com/lists/oss-security/2020/04/22/2
https://github.com/irsl/CVE-2020-1967
https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44440
https://lists.apache.org/thread.html/[email protected]%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/[email protected]%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/[email protected]%3Cdev.tomcat.apache.org%3E
https://security.FreeBSD.org/advisories/FreeBSD-SA-20:11.openssl.asc
https://security.gentoo.org/glsa/202004-10
https://security.netapp.com/advisory/ntap-20200424-0003/
https://security.netapp.com/advisory/ntap-20200717-0004/
https://www.debian.org/security/2020/dsa-4661
https://www.openssl.org/news/secadv/20200421.txt
https://www.oracle.com/security-alerts/cpujan2021.html
https://www.oracle.com/security-alerts/cpujul2020.html
https://www.oracle.com/security-alerts/cpuoct2020.html
https://www.synology.com/security/advisory/Synology_SA_20_05
https://www.synology.com/security/advisory/Synology_SA_20_05_OpenSSL
https://www.tenable.com/security/tns-2020-03
Source: MITRE
Published: 2020-04-21
Updated: 2021-02-09
Type: CWE-476
Base Score: 5
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P
Impact Score: 2.9
Exploitability Score: 10
Severity: MEDIUM
Base Score: 7.5
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Impact Score: 3.6
Exploitability Score: 3.9
Severity: HIGH
OR
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* versions from 1.1.1d to 1.1.1f (inclusive)
OR
OR
OR
cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
OR
cpe:2.3:a:oracle:enterprise_manager_for_storage_management:13.3.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:enterprise_manager_for_storage_management:13.4.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:enterprise_manager_ops_center:12.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:http_server:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:* versions up to 5.6.48 (inclusive)
cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:* versions from 5.7.0 to 5.7.30 (inclusive)
cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:* versions from 8.0.0 to 8.0.20 (inclusive)
cpe:2.3:a:oracle:mysql_connectors:*:*:*:*:*:*:*:* versions up to 8.0.20 (inclusive)
cpe:2.3:a:oracle:mysql_enterprise_monitor:*:*:*:*:*:*:*:* versions up to 4.0.12 (inclusive)
cpe:2.3:a:oracle:mysql_enterprise_monitor:*:*:*:*:*:*:*:* versions from 8.0.0 to 8.0.20 (inclusive)
cpe:2.3:a:oracle:mysql_workbench:*:*:*:*:*:*:*:* versions up to 8.0.21 (inclusive)
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.56:*:*:*:*:*:*:*
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.57:*:*:*:*:*:*:*
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58:*:*:*:*:*:*:*
OR
cpe:2.3:a:netapp:active_iq_unified_manager:*:*:*:*:*:windows:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:*:*:*:*:*:vmware_vsphere:*:*
cpe:2.3:a:netapp:e-series_performance_analyzer:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:oncommand_workflow_automation:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:smi-s_provider:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:snapcenter:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:steelstore_cloud_integrated_storage:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:brocade_fabric_operating_system_firmware:-:*:*:*:*:*:*:*
OR
OR
ID | Name | Product | Family | Severity |
---|---|---|---|---|
144584 | Tenable SecurityCenter < 5.17.0 Multiple Vulnerabilities (TNS-2020-11) | Nessus | Misc. | medium |
142212 | Oracle Fusion Middleware Oracle HTTP Server (Oct 2020 CPU) | Nessus | Web Servers | high |
141809 | Oracle Enterprise Manager Cloud Control (Oct 2020 CPU) | Nessus | Misc. | medium |
138995 | SUSE SLED15 / SLES15 Security Update : rust, rust-cbindgen (SUSE-SU-2020:2041-1) | Nessus | SuSE Local Security Checks | medium |
138732 | openSUSE Security Update : rust / rust-cbindgen (openSUSE-2020-945) | Nessus | SuSE Local Security Checks | medium |
138725 | openSUSE Security Update : rust / rust-cbindgen (openSUSE-2020-933) | Nessus | SuSE Local Security Checks | medium |
138607 | Oracle MySQL Connectors (Jul 2020 CPU) | Nessus | Misc. | medium |
138571 | MySQL 5.6.x < 5.6.49 Multiple Vulnerabilities (Jul 2020 CPU) | Nessus | Databases | medium |
138570 | MySQL 5.7.x < 5.7.31 Multiple Vulnerabilities (Jul 2020 CPU) | Nessus | Databases | medium |
138568 | MySQL Enterprise Monitor 4.0.x < 4.0.13.5349 / 8.0.x < 8.0.21.1240 (Jul 2020 CPU) | Nessus | CGI abuses | medium |
138560 | MySQL 8.0.x < 8.0.21 Multiple Vulnerabilities (Jul 2020 CPU) | Nessus | Databases | medium |
137757 | Tenable Nessus Agent < 7.6.3 Third Party Vulnerability (OpenSSL) (TNS-2020-03) | Nessus | Misc. | medium |
137031 | EulerOS 2.0 SP5 : openssl111d (EulerOS-SA-2020-1613) | Nessus | Huawei Local Security Checks | medium |
136439 | Fedora 31 : 1:openssl (2020-d7b29838f6) | Nessus | Fedora Local Security Checks | medium |
136304 | FreeBSD : Gitlab -- Multiple Vulnerabilities (e8483115-8b8e-11ea-bdcf-001b217b3468) | Nessus | FreeBSD Local Security Checks | medium |
136155 | Fedora 30 : 1:openssl (2020-da2d1ef2d7) | Nessus | Fedora Local Security Checks | medium |
135946 | GLSA-202004-10 : OpenSSL: Multiple vulnerabilities | Nessus | Gentoo Local Security Checks | medium |
135919 | OpenSSL 1.1.1 < 1.1.1g Vulnerability | Nessus | Web Servers | medium |
135893 | SUSE SLES12 Security Update : openssl-1_1 (SUSE-SU-2020:1058-1) | Nessus | SuSE Local Security Checks | medium |
135880 | FreeBSD : OpenSSL remote denial of service vulnerability (012809ce-83f3-11ea-92ab-00163e433440) | Nessus | FreeBSD Local Security Checks | medium |
135879 | Debian DSA-4661-1 : openssl - security update | Nessus | Debian Local Security Checks | medium |
135873 | Photon OS 3.0: Nxtgn PHSA-2020-3.0-0082 | Nessus | PhotonOS Local Security Checks | medium |