Back

MEDIUM

openssl: Malformed X.509 IPAdressFamily could cause OOB read

Published Aug 28, 2017

Description

While parsing an IPAddressFamily extension in an X.509 certificate, it is possible to do a one-byte overread. This would result in an incorrect text display of the certificate. This bug has been present since 2006 and is present in all versions of OpenSSL before 1.0.2m and 1.1.0g.

Affected products

Remediation

Red Hat statement

This flaw only exhibits itself when: 1. OpenSSL is used to display details of a local or a remote certificate. 2. The certificate contains the uncommon RFC 3779 IPAddressFamily extension. The maximum impact of this flaw is garbled information being displayed, there is no impact on the availability of service using such a certificate. Also this flaw can NOT be used to create specially-crafted certificates. Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Metrics

References (31)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner openssl
Published Aug 28, 2017
Updated Sep 16, 2024
Reserved Dec 16, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Aug 28, 2017