X.509 Email Address Variable Length Buffer Overflow
Published Nov 1, 2022
7.5
HIGHCVSS 3.1
EPSS 92.49%
Description
A buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification and requires either a CA to have signed a malicious certificate or for an application to continue certificate verification despite failure to construct a path to a trusted issuer. An attacker can craft a malicious email address in a certificate to overflow an arbitrary number of bytes containing the `.' character (decimal 46) on the stack. This buffer overflow could result in a crash (causing a denial of service). In a TLS client, this can be triggered by connecting to a malicious server. In a TLS server, this can be triggered if the server requests client authentication and a malicious client connects.
Affected products
-
- Version 3.0.0StatusaffectedConstraints<3.0.7
- Version
No data.
Red Hat Enterprise Linux 9
openssl-1:3.0.1-43.el9_0
Fixed · RHSA-2022:7288
Red Hat Enterprise Linux 9
openssl-1:3.0.1-43.el9_0
Fixed · RHSA-2022:7288
Red Hat Enterprise Linux 9
rhel9/openssl:9.0-25
Fixed · RHSA-2022:7384
Red Hat Enterprise Linux 9
ubi9/openssl:9.0-25
Fixed · RHSA-2022:7384
Logging Subsystem for Red Hat OpenShift
openshift-logging/fluentd-rhel9
Under investigation
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/management-ingress-rhel8
Not affected
Red Hat Enterprise Linux 6
openssl
Not affected
Red Hat Enterprise Linux 6
openssl098e
Not affected
Red Hat Enterprise Linux 7
openssl
Not affected
Red Hat Enterprise Linux 7
openssl098e
Not affected
Red Hat Enterprise Linux 7
ovmf
Not affected
Red Hat Enterprise Linux 8
compat-openssl10
Not affected
Red Hat Enterprise Linux 8
edk2
Not affected
Red Hat Enterprise Linux 8
openssl
Not affected
Red Hat Enterprise Linux 8
shim
Not affected
Red Hat Enterprise Linux 9
compat-openssl11
Not affected
Red Hat Enterprise Linux 9
edk2
Not affected
Red Hat Enterprise Linux 9
shim
Not affected
Red Hat JBoss Core Services
jbcs-httpd24-openssl
Not affected
Red Hat JBoss Enterprise Application Platform 6
openssl
Not affected
Red Hat JBoss Web Server 3
openssl
Not affected
Red Hat JBoss Web Server 5
openssl
Not affected
Red Hat Virtualization 4
redhat-virtualization-host
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 9 | openssl-1:3.0.1-43.el9_0 | Fixed | RHSA-2022:7288 |
| Red Hat Enterprise Linux 9 | openssl-1:3.0.1-43.el9_0 | Fixed | RHSA-2022:7288 |
| Red Hat Enterprise Linux 9 | rhel9/openssl:9.0-25 | Fixed | RHSA-2022:7384 |
| Red Hat Enterprise Linux 9 | ubi9/openssl:9.0-25 | Fixed | RHSA-2022:7384 |
| Logging Subsystem for Red Hat OpenShift | openshift-logging/fluentd-rhel9 | Under investigation | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/management-ingress-rhel8 | Not affected | n/a |
| Red Hat Enterprise Linux 6 | openssl | Not affected | n/a |
| Red Hat Enterprise Linux 6 | openssl098e | Not affected | n/a |
| Red Hat Enterprise Linux 7 | openssl | Not affected | n/a |
| Red Hat Enterprise Linux 7 | openssl098e | Not affected | n/a |
| Red Hat Enterprise Linux 7 | ovmf | Not affected | n/a |
| Red Hat Enterprise Linux 8 | compat-openssl10 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | edk2 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | openssl | Not affected | n/a |
| Red Hat Enterprise Linux 8 | shim | Not affected | n/a |
| Red Hat Enterprise Linux 9 | compat-openssl11 | Not affected | n/a |
| Red Hat Enterprise Linux 9 | edk2 | Not affected | n/a |
| Red Hat Enterprise Linux 9 | shim | Not affected | n/a |
| Red Hat JBoss Core Services | jbcs-httpd24-openssl | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | openssl | Not affected | n/a |
| Red Hat JBoss Web Server 3 | openssl | Not affected | n/a |
| Red Hat JBoss Web Server 5 | openssl | Not affected | n/a |
| Red Hat Virtualization 4 | redhat-virtualization-host | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
As per upstream, the most common situation where this can be triggered is when a server requests client authentication after a malicious client connects. A client connecting to a malicious server is also believed to be vulnerable in the same manner. Only OpenSSL versions 3.0.0 to 3.0.6 are vulnerable to this attack.
References (55)
- http://packetstormsecurity.com/files/169687/OpenSSL-Security-Advisory-20221101.html
- http://www.openwall.com/lists/oss-security/2022/11/01/15
- http://www.openwall.com/lists/oss-security/2022/11/01/16
- http://www.openwall.com/lists/oss-security/2022/11/01/17
- http://www.openwall.com/lists/oss-security/2022/11/01/18
- http://www.openwall.com/lists/oss-security/2022/11/01/19
- http://www.openwall.com/lists/oss-security/2022/11/01/20
- http://www.openwall.com/lists/oss-security/2022/11/01/21
- http://www.openwall.com/lists/oss-security/2022/11/01/24
- http://www.openwall.com/lists/oss-security/2022/11/02/1
- http://www.openwall.com/lists/oss-security/2022/11/02/10
- http://www.openwall.com/lists/oss-security/2022/11/02/11
- http://www.openwall.com/lists/oss-security/2022/11/02/12
- http://www.openwall.com/lists/oss-security/2022/11/02/13
- http://www.openwall.com/lists/oss-security/2022/11/02/14
- http://www.openwall.com/lists/oss-security/2022/11/02/15
- http://www.openwall.com/lists/oss-security/2022/11/02/2
- http://www.openwall.com/lists/oss-security/2022/11/02/3
- http://www.openwall.com/lists/oss-security/2022/11/02/5
- http://www.openwall.com/lists/oss-security/2022/11/02/6
- http://www.openwall.com/lists/oss-security/2022/11/02/7
- http://www.openwall.com/lists/oss-security/2022/11/02/9
- http://www.openwall.com/lists/oss-security/2022/11/03/1
- http://www.openwall.com/lists/oss-security/2022/11/03/10
- http://www.openwall.com/lists/oss-security/2022/11/03/11
- http://www.openwall.com/lists/oss-security/2022/11/03/2
- http://www.openwall.com/lists/oss-security/2022/11/03/3
- http://www.openwall.com/lists/oss-security/2022/11/03/5
- http://www.openwall.com/lists/oss-security/2022/11/03/6
- http://www.openwall.com/lists/oss-security/2022/11/03/7
- http://www.openwall.com/lists/oss-security/2022/11/03/9
- https://access.redhat.com/security/cve/CVE-2022-3786 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2139104 Issue Tracking
- https://cert-portal.siemens.com/productcert/html/ssa-408105.html
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=c42165b5706e42f67ef8ef4c351a9a4c5d21639a
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=c42165b5706e42f67ef8ef4c351a9a4c5d21639a patchVendor Advisory
- https://github.com/advisories/GHSA-h8jm-2x53-xhp5 Advisory
- https://github.com/alexcrichton/openssl-src-rs/commit/4a31c14f31e1a08c18893a37e304dd1dd4b7daa3
- https://github.com/openssl/openssl/commit/fe3b639dc19b325846f4f6801f2f4604f56e3de3
- https://github.com/rustsec/advisory-db/pull/1452
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/63YRPWPUSX3MBHNPIEJZDKQT6YA7UF6S/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DWP23EZYOBDJQP7HP4YU7W2ABU2YDITS/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/63YRPWPUSX3MBHNPIEJZDKQT6YA7UF6S/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DWP23EZYOBDJQP7HP4YU7W2ABU2YDITS/
- https://nvd.nist.gov/vuln/detail/CVE-2022-3786
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0023
- https://rustsec.org/advisories/RUSTSEC-2022-0065.html
- https://security.gentoo.org/glsa/202211-01
- https://security.netapp.com/advisory/ntap-20221102-0001/
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-openssl-W9sdCc2a
- https://www.cve.org/CVERecord?id=CVE-2022-3786
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00789.html
- https://www.kb.cert.org/vuls/id/794340
- https://www.openssl.org/blog/blog/2022/11/01/email-address-overflows/
- https://www.openssl.org/news/secadv/20221101.txt vendor-advisoryVendor Advisory
Change history (0)
No recorded changes yet.