CVE-2023-0216

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
08/02/2023
Last modified:
04/11/2025

Description

An invalid pointer dereference on read can be triggered when an<br /> application tries to load malformed PKCS7 data with the<br /> d2i_PKCS7(), d2i_PKCS7_bio() or d2i_PKCS7_fp() functions.<br /> <br /> The result of the dereference is an application crash which could<br /> lead to a denial of service attack. The TLS implementation in OpenSSL<br /> does not call this function however third party applications might<br /> call these functions on untrusted data.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* 3.0.0 (including) 3.0.7 (including)
cpe:2.3:a:stormshield:stormshield_management_center:*:*:*:*:*:*:*:* 3.3.3 (excluding)