CVE-2023-0401
Gravedad CVSS v3.1:
ALTA
Tipo:
CWE-476
Desreferencia a puntero nulo (NULL)
Fecha de publicación:
08/02/2023
Última modificación:
04/11/2025
Descripción
*** Pendiente de traducción *** A NULL pointer can be dereferenced when signatures are being<br />
verified on PKCS7 signed or signedAndEnveloped data. In case the hash<br />
algorithm used for the signature is known to the OpenSSL library but<br />
the implementation of the hash algorithm is not available the digest<br />
initialization will fail. There is a missing check for the return<br />
value from the initialization function which later leads to invalid<br />
usage of the digest API most likely leading to a crash.<br />
<br />
The unavailability of an algorithm can be caused by using FIPS<br />
enabled configuration of providers or more commonly by not loading<br />
the legacy provider.<br />
<br />
PKCS7 data is processed by the SMIME library calls and also by the<br />
time stamp (TS) library calls. The TLS implementation in OpenSSL does<br />
not call these functions however third party applications would be<br />
affected if they call these functions to verify signatures on untrusted<br />
data.
Impacto
Puntuación base 3.x
7.50
Gravedad 3.x
ALTA
Productos y versiones vulnerables
| CPE | Desde | Hasta |
|---|---|---|
| cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* | 3.0.0 (incluyendo) | 3.0.7 (incluyendo) |
| cpe:2.3:a:stormshield:stormshield_management_center:*:*:*:*:*:*:*:* | 3.3.3 (excluyendo) |
Para consultar la lista completa de nombres de CPE con productos y versiones, ver esta página
Referencias a soluciones, herramientas e información
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba%3Dcommitdiff%3Bh%3Dd3b6dfd70db844c4499bec6ad6601623a565e674
- https://security.gentoo.org/glsa/202402-08
- https://www.openssl.org/news/secadv/20230207.txt
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba%3Dcommitdiff%3Bh%3Dd3b6dfd70db844c4499bec6ad6601623a565e674
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0003
- https://security.gentoo.org/glsa/202402-08
- https://www.openssl.org/news/secadv/20230207.txt



