Description
Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signature_algorithms_cert" TLS extension. The crash occurs if an invalid or unrecognised signature algorithm is received from the peer. This could be exploited by a malicious peer in a Denial of Service attack. OpenSSL version 1.1.1d, 1.1.1e, and 1.1.1f are affected by this issue. This issue did not affect OpenSSL versions prior to 1.1.1d. Fixed in OpenSSL 1.1.1g (Affected 1.1.1d-1.1.1f).
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-4661-1 | openssl security update |
Github GHSA |
GHSA-jq65-29v4-4x35 | Null pointer deference in openssl-src |
References
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Subscriptions
Broadcom
Subscribe
Fabric Operating System
Subscribe
Debian
Subscribe
Debian Linux
Subscribe
Fedoraproject
Subscribe
Fedora
Subscribe
Freebsd
Subscribe
Freebsd
Subscribe
Jdedwards
Subscribe
Enterpriseone
Subscribe
Netapp
Subscribe
Active Iq Unified Manager
Subscribe
E-series Performance Analyzer
Subscribe
Oncommand Insight
Subscribe
Oncommand Workflow Automation
Subscribe
Smi-s Provider
Subscribe
Snapcenter
Subscribe
Steelstore Cloud Integrated Storage
Subscribe
Openssl
Subscribe
Openssl
Subscribe
Opensuse
Subscribe
Leap
Subscribe
Oracle
Subscribe
Application Server
Subscribe
Enterprise Manager Base Platform
Subscribe
Enterprise Manager For Storage Management
Subscribe
Enterprise Manager Ops Center
Subscribe
Http Server
Subscribe
Jd Edwards World Security
Subscribe
Mysql
Subscribe
Mysql Connectors
Subscribe
Mysql Enterprise Monitor
Subscribe
Mysql Workbench
Subscribe
Peoplesoft Enterprise Peopletools
Subscribe
Tenable
Subscribe
Log Correlation Engine
Subscribe
Status: PUBLISHED
Assigner: openssl
Published:
Updated: 2024-09-17T03:13:46.200Z
Reserved: 2019-12-03T00:00:00.000Z
Link: CVE-2020-1967
No data.
Status : Modified
Published: 2020-04-21T14:15:11.287
Modified: 2024-11-21T05:11:45.023
Link: CVE-2020-1967
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
Github GHSA