X.400 address type confusion in X.509 GeneralName
Published Feb 8, 2023
7.4
HIGHCVSS 3.1
EPSS 59.50%
Description
There is a type confusion vulnerability relating to X.400 address processing inside an X.509 GeneralName. X.400 addresses were parsed as an ASN1_STRING but the public structure definition for GENERAL_NAME incorrectly specified the type of the x400Address field as ASN1_TYPE. This field is subsequently interpreted by the OpenSSL function GENERAL_NAME_cmp as an ASN1_TYPE rather than an ASN1_STRING.
When CRL checking is enabled (i.e. the application sets the X509_V_FLAG_CRL_CHECK flag), this vulnerability may allow an attacker to pass arbitrary pointers to a memcmp call, enabling them to read memory contents or enact a denial of service. In most cases, the attack requires the attacker to provide both the certificate chain and CRL, neither of which need to have a valid signature. If the attacker only controls one of these inputs, the other input must already contain an X.400 address as a CRL distribution point, which is uncommon. As such, this vulnerability is most likely to only affect applications which have implemented their own functionality for retrieving CRLs over a network.
Affected products
-
- Version 1.0.2StatusaffectedConstraints<1.0.2zg
- Version 1.1.1StatusaffectedConstraints<1.1.1t
- Version 3.0.0StatusaffectedConstraints<3.0.8
- Version
Configuration 1
Configuration 2
- < 3.3.3
- ≥ 2.7.0 · < 2.7.11
- ≥ 2.8.0 · < 3.7.34
- ≥ 3.8.0 · < 3.11.22
- ≥ 4.0.0 · < 4.3.16
- ≥ 4.4.0 · < 4.6.3
No data.
JBoss Core Services for RHEL 8
jbcs-httpd24-openssl-1:1.1.1k-14.el8jbcs
Fixed · RHSA-2023:3354
JBoss Core Services on RHEL 7
jbcs-httpd24-openssl-1:1.1.1k-14.el7jbcs
Fixed · RHSA-2023:3354
RHOL-5.9-RHEL-9
openshift-logging/cluster-logging-operator-bundle:v5.9.6-22
Fixed · RHSA-2024:6095
RHOL-5.9-RHEL-9
openshift-logging/cluster-logging-rhel9-operator:v5.9.6-11
Fixed · RHSA-2024:6095
RHOL-5.9-RHEL-9
openshift-logging/eventrouter-rhel9:v0.4.0-290
Fixed · RHSA-2024:6095
RHOL-5.9-RHEL-9
openshift-logging/fluentd-rhel9:v5.9.6-4
Fixed · RHSA-2024:6095
RHOL-5.9-RHEL-9
openshift-logging/log-file-metric-exporter-rhel9:v1.1.0-270
Fixed · RHSA-2024:6095
RHOL-5.9-RHEL-9
openshift-logging/logging-loki-rhel9:v3.1.0-18
Fixed · RHSA-2024:6095
RHOL-5.9-RHEL-9
openshift-logging/logging-view-plugin-rhel9:v5.9.6-3
Fixed · RHSA-2024:6095
RHOL-5.9-RHEL-9
openshift-logging/loki-operator-bundle:v5.9.6-15
Fixed · RHSA-2024:6095
RHOL-5.9-RHEL-9
openshift-logging/loki-rhel9-operator:v5.9.6-5
Fixed · RHSA-2024:6095
RHOL-5.9-RHEL-9
openshift-logging/lokistack-gateway-rhel9:v0.1.0-639
Fixed · RHSA-2024:6095
RHOL-5.9-RHEL-9
openshift-logging/opa-openshift-rhel9:v0.1.0-277
Fixed · RHSA-2024:6095
RHOL-5.9-RHEL-9
openshift-logging/vector-rhel9:v0.34.1-16
Fixed · RHSA-2024:6095
Red Hat Enterprise Linux 6 Extended Lifecycle Support
openssl-0:1.0.1e-61.el6_10
Fixed · RHSA-2023:1438
Red Hat Enterprise Linux 7
openssl-1:1.0.2k-26.el7_9
Fixed · RHSA-2023:1335
Red Hat Enterprise Linux 7.7 Advanced Update Support
openssl-1:1.0.2k-21.el7_7.1
Fixed · RHSA-2024:5136
Red Hat Enterprise Linux 8
compat-openssl10-1:1.0.2o-4.el8_10.1
Fixed · RHSA-2025:7895
Red Hat Enterprise Linux 8
edk2-0:20220126gitbb1bba3d77-4.el8
Fixed · RHSA-2023:2932
Red Hat Enterprise Linux 8
openssl-1:1.1.1k-9.el8_7
Fixed · RHSA-2023:1405
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions
openssl-1:1.1.1c-6.el8_1
Fixed · RHSA-2023:1437
Red Hat Enterprise Linux 8.2 Advanced Update Support
edk2-0:20190829git37eef91017ad-9.el8_2.2
Fixed · RHSA-2023:4124
Red Hat Enterprise Linux 8.2 Advanced Update Support
openssl-1:1.1.1c-21.el8_2
Fixed · RHSA-2023:1439
Red Hat Enterprise Linux 8.2 Telecommunications Update Service
edk2-0:20190829git37eef91017ad-9.el8_2.2
Fixed · RHSA-2023:4124
Red Hat Enterprise Linux 8.2 Telecommunications Update Service
openssl-1:1.1.1c-21.el8_2
Fixed · RHSA-2023:1439
Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions
edk2-0:20190829git37eef91017ad-9.el8_2.2
Fixed · RHSA-2023:4124
Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions
openssl-1:1.1.1c-21.el8_2
Fixed · RHSA-2023:1439
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
edk2-0:20200602gitca407c7246bf-4.el8_4.3
Fixed · RHSA-2023:4252
Red Hat Enterprise Linux 8.4 Extended Update Support
openssl-1:1.1.1g-18.el8_4
Fixed · RHSA-2023:1440
Red Hat Enterprise Linux 8.4 Telecommunications Update Service
edk2-0:20200602gitca407c7246bf-4.el8_4.3
Fixed · RHSA-2023:4252
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions
edk2-0:20200602gitca407c7246bf-4.el8_4.3
Fixed · RHSA-2023:4252
Red Hat Enterprise Linux 8.6 Extended Update Support
edk2-0:20220126gitbb1bba3d77-2.el8_6.1
Fixed · RHSA-2023:4128
Red Hat Enterprise Linux 8.6 Extended Update Support
openssl-1:1.1.1k-8.el8_6
Fixed · RHSA-2023:1441
Red Hat Enterprise Linux 9
compat-openssl11-1:1.1.1k-5.el9_6.1
Fixed · RHSA-2025:7937
Red Hat Enterprise Linux 9
edk2-0:20221207gitfff6d81270b5-9.el9_2
Fixed · RHSA-2023:2165
Red Hat Enterprise Linux 9
openssl-1:3.0.1-47.el9_1
Fixed · RHSA-2023:0946
Red Hat Enterprise Linux 9
openssl-1:3.0.1-47.el9_1
Fixed · RHSA-2023:0946
Red Hat Enterprise Linux 9.0 Extended Update Support
edk2-0:20220126gitbb1bba3d77-3.el9_0.2
Fixed · RHSA-2023:2022
Red Hat Enterprise Linux 9.0 Extended Update Support
openssl-1:3.0.1-46.el9_0
Fixed · RHSA-2023:1199
Red Hat Enterprise Linux 9.4 Extended Update Support
compat-openssl11-1:1.1.1k-5.el9_4.1
Fixed · RHSA-2025:7733
Red Hat JBoss Web Server 5
openssl
Fixed · RHSA-2023:3421
Red Hat JBoss Web Server 5.7 on RHEL 7
jws5-tomcat-native-0:1.2.31-14.redhat_14.el7jws
Fixed · RHSA-2023:3420
Red Hat JBoss Web Server 5.7 on RHEL 8
jws5-tomcat-native-0:1.2.31-14.redhat_14.el8jws
Fixed · RHSA-2023:3420
Red Hat JBoss Web Server 5.7 on RHEL 9
jws5-tomcat-native-0:1.2.31-14.redhat_14.el9jws
Fixed · RHSA-2023:3420
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8
redhat-virtualization-host-0:4.5.3-202309130206_8.6
Fixed · RHSA-2023:5209
Red Hat Enterprise Linux 7
ovmf
Will not fix
Red Hat Enterprise Linux 8
shim
Not affected
Red Hat Enterprise Linux 9
shim
Not affected
Red Hat JBoss Web Server 3
openssl
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| JBoss Core Services for RHEL 8 | jbcs-httpd24-openssl-1:1.1.1k-14.el8jbcs | Fixed | RHSA-2023:3354 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-openssl-1:1.1.1k-14.el7jbcs | Fixed | RHSA-2023:3354 |
| RHOL-5.9-RHEL-9 | openshift-logging/cluster-logging-operator-bundle:v5.9.6-22 | Fixed | RHSA-2024:6095 |
| RHOL-5.9-RHEL-9 | openshift-logging/cluster-logging-rhel9-operator:v5.9.6-11 | Fixed | RHSA-2024:6095 |
| RHOL-5.9-RHEL-9 | openshift-logging/eventrouter-rhel9:v0.4.0-290 | Fixed | RHSA-2024:6095 |
| RHOL-5.9-RHEL-9 | openshift-logging/fluentd-rhel9:v5.9.6-4 | Fixed | RHSA-2024:6095 |
| RHOL-5.9-RHEL-9 | openshift-logging/log-file-metric-exporter-rhel9:v1.1.0-270 | Fixed | RHSA-2024:6095 |
| RHOL-5.9-RHEL-9 | openshift-logging/logging-loki-rhel9:v3.1.0-18 | Fixed | RHSA-2024:6095 |
| RHOL-5.9-RHEL-9 | openshift-logging/logging-view-plugin-rhel9:v5.9.6-3 | Fixed | RHSA-2024:6095 |
| RHOL-5.9-RHEL-9 | openshift-logging/loki-operator-bundle:v5.9.6-15 | Fixed | RHSA-2024:6095 |
| RHOL-5.9-RHEL-9 | openshift-logging/loki-rhel9-operator:v5.9.6-5 | Fixed | RHSA-2024:6095 |
| RHOL-5.9-RHEL-9 | openshift-logging/lokistack-gateway-rhel9:v0.1.0-639 | Fixed | RHSA-2024:6095 |
| RHOL-5.9-RHEL-9 | openshift-logging/opa-openshift-rhel9:v0.1.0-277 | Fixed | RHSA-2024:6095 |
| RHOL-5.9-RHEL-9 | openshift-logging/vector-rhel9:v0.34.1-16 | Fixed | RHSA-2024:6095 |
| Red Hat Enterprise Linux 6 Extended Lifecycle Support | openssl-0:1.0.1e-61.el6_10 | Fixed | RHSA-2023:1438 |
| Red Hat Enterprise Linux 7 | openssl-1:1.0.2k-26.el7_9 | Fixed | RHSA-2023:1335 |
| Red Hat Enterprise Linux 7.7 Advanced Update Support | openssl-1:1.0.2k-21.el7_7.1 | Fixed | RHSA-2024:5136 |
| Red Hat Enterprise Linux 8 | compat-openssl10-1:1.0.2o-4.el8_10.1 | Fixed | RHSA-2025:7895 |
| Red Hat Enterprise Linux 8 | edk2-0:20220126gitbb1bba3d77-4.el8 | Fixed | RHSA-2023:2932 |
| Red Hat Enterprise Linux 8 | openssl-1:1.1.1k-9.el8_7 | Fixed | RHSA-2023:1405 |
| Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions | openssl-1:1.1.1c-6.el8_1 | Fixed | RHSA-2023:1437 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | edk2-0:20190829git37eef91017ad-9.el8_2.2 | Fixed | RHSA-2023:4124 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | openssl-1:1.1.1c-21.el8_2 | Fixed | RHSA-2023:1439 |
| Red Hat Enterprise Linux 8.2 Telecommunications Update Service | edk2-0:20190829git37eef91017ad-9.el8_2.2 | Fixed | RHSA-2023:4124 |
| Red Hat Enterprise Linux 8.2 Telecommunications Update Service | openssl-1:1.1.1c-21.el8_2 | Fixed | RHSA-2023:1439 |
| Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions | edk2-0:20190829git37eef91017ad-9.el8_2.2 | Fixed | RHSA-2023:4124 |
| Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions | openssl-1:1.1.1c-21.el8_2 | Fixed | RHSA-2023:1439 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | edk2-0:20200602gitca407c7246bf-4.el8_4.3 | Fixed | RHSA-2023:4252 |
| Red Hat Enterprise Linux 8.4 Extended Update Support | openssl-1:1.1.1g-18.el8_4 | Fixed | RHSA-2023:1440 |
| Red Hat Enterprise Linux 8.4 Telecommunications Update Service | edk2-0:20200602gitca407c7246bf-4.el8_4.3 | Fixed | RHSA-2023:4252 |
| Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | edk2-0:20200602gitca407c7246bf-4.el8_4.3 | Fixed | RHSA-2023:4252 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | edk2-0:20220126gitbb1bba3d77-2.el8_6.1 | Fixed | RHSA-2023:4128 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | openssl-1:1.1.1k-8.el8_6 | Fixed | RHSA-2023:1441 |
| Red Hat Enterprise Linux 9 | compat-openssl11-1:1.1.1k-5.el9_6.1 | Fixed | RHSA-2025:7937 |
| Red Hat Enterprise Linux 9 | edk2-0:20221207gitfff6d81270b5-9.el9_2 | Fixed | RHSA-2023:2165 |
| Red Hat Enterprise Linux 9 | openssl-1:3.0.1-47.el9_1 | Fixed | RHSA-2023:0946 |
| Red Hat Enterprise Linux 9 | openssl-1:3.0.1-47.el9_1 | Fixed | RHSA-2023:0946 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | edk2-0:20220126gitbb1bba3d77-3.el9_0.2 | Fixed | RHSA-2023:2022 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | openssl-1:3.0.1-46.el9_0 | Fixed | RHSA-2023:1199 |
| Red Hat Enterprise Linux 9.4 Extended Update Support | compat-openssl11-1:1.1.1k-5.el9_4.1 | Fixed | RHSA-2025:7733 |
| Red Hat JBoss Web Server 5 | openssl | Fixed | RHSA-2023:3421 |
| Red Hat JBoss Web Server 5.7 on RHEL 7 | jws5-tomcat-native-0:1.2.31-14.redhat_14.el7jws | Fixed | RHSA-2023:3420 |
| Red Hat JBoss Web Server 5.7 on RHEL 8 | jws5-tomcat-native-0:1.2.31-14.redhat_14.el8jws | Fixed | RHSA-2023:3420 |
| Red Hat JBoss Web Server 5.7 on RHEL 9 | jws5-tomcat-native-0:1.2.31-14.redhat_14.el9jws | Fixed | RHSA-2023:3420 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | redhat-virtualization-host-0:4.5.3-202309130206_8.6 | Fixed | RHSA-2023:5209 |
| Red Hat Enterprise Linux 7 | ovmf | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | shim | Not affected | n/a |
| Red Hat Enterprise Linux 9 | shim | Not affected | n/a |
| Red Hat JBoss Web Server 3 | openssl | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
For shim in Red Hat Enterprise Linux 8 & 9, is not affected as shim doesn't support any CRL processing.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (17)
- https://access.redhat.com/security/cve/CVE-2023-0286 Vendor Advisory
- https://access.redhat.com/security/cve/cve-2023-0286
- https://bugzilla.redhat.com/show_bug.cgi?id=2164440 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-0817 Advisory
- https://ftp.openbsd.org/pub/OpenBSD/LibreSSL/libressl-3.6.2-relnotes.txt Third Party Advisory
- https://ftp.openbsd.org/pub/OpenBSD/patches/7.2/common/018_x509.patch.sig Third Party Advisory
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=2c6c9d439b484e1ba9830d8454a34fa4f80fdfe9 patchVendor Advisory
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=2f7530077e0ef79d98718138716bc51ca0cad658 patchVendor Advisory
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=fd2af07dc083a350c959147097003a14a5e8ac4d patchVendor Advisory
- https://github.com/advisories/GHSA-x4qr-2fvf-3mr5 Advisory
- https://github.com/pyca/cryptography/security/advisories/GHSA-x4qr-2fvf-3mr5
- https://nvd.nist.gov/vuln/detail/CVE-2023-0286
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0003
- https://rustsec.org/advisories/RUSTSEC-2023-0006.html
- https://security.gentoo.org/glsa/202402-08
- https://www.cve.org/CVERecord?id=CVE-2023-0286
- https://www.openssl.org/news/secadv/20230207.txt vendor-advisoryVendor Advisory
Change history (0)
No recorded changes yet.