{"api_version":"1","generated_at":"2026-04-10T06:33:19+00:00","cve":"CVE-2023-5678","urls":{"html":"https://cve.report/CVE-2023-5678","api":"https://cve.report/api/cve/CVE-2023-5678.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2023-5678","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2023-5678"},"summary":{"title":"CVE-2023-5678","description":"Issue summary: Generating excessively long X9.42 DH keys or checking\nexcessively long X9.42 DH keys or parameters may be very slow.\n\nImpact summary: Applications that use the functions DH_generate_key() to\ngenerate an X9.42 DH key may experience long delays.  Likewise, applications\nthat use DH_check_pub_key(), DH_check_pub_key_ex() or EVP_PKEY_public_check()\nto check an X9.42 DH key or X9.42 DH parameters may experience long delays.\nWhere the key or parameters that are being checked have been obtained from\nan untrusted source this may lead to a Denial of Service.\n\nWhile DH_check() performs all the necessary checks (as of CVE-2023-3817),\nDH_check_pub_key() doesn't make any of these checks, and is therefore\nvulnerable for excessively large P and Q parameters.\n\nLikewise, while DH_generate_key() performs a check for an excessively large\nP, it doesn't check for an excessively large Q.\n\nAn application that calls DH_generate_key() or DH_check_pub_key() and\nsupplies a key or parameters obtained from an untrusted source could be\nvulnerable to a Denial of Service attack.\n\nDH_generate_key() and DH_check_pub_key() are also called by a number of\nother OpenSSL functions.  An application calling any of those other\nfunctions may similarly be affected.  The other functions affected by this\nare DH_check_pub_key_ex(), EVP_PKEY_public_check(), and EVP_PKEY_generate().\n\nAlso vulnerable are the OpenSSL pkey command line application when using the\n\"-pubcheck\" option, as well as the OpenSSL genpkey command line application.\n\nThe OpenSSL SSL/TLS implementation is not affected by this issue.\n\nThe OpenSSL 3.0 and 3.1 FIPS providers are not affected by this issue.","state":"PUBLIC","assigner":"openssl-security@openssl.org","published_at":"2023-11-06 16:15:00","updated_at":"2023-11-30 22:15:00"},"problem_types":["CWE-754"],"metrics":[],"references":[{"url":"https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=ddeb4b6c6d527e54ce9a99cba785c0f7776e54b6","name":"https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=ddeb4b6c6d527e54ce9a99cba785c0f7776e54b6","refsource":"MISC","tags":[],"title":"git.openssl.org Git - openssl.git/commitdiff","mime":"text/xml","httpstatus":"200","archivestatus":"404"},{"url":"https://security.netapp.com/advisory/ntap-20231130-0010/","name":"https://security.netapp.com/advisory/ntap-20231130-0010/","refsource":"","tags":[],"title":"","mime":"","httpstatus":"200","archivestatus":"404"},{"url":"https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=34efaef6c103d636ab507a0cc34dca4d3aecc055","name":"https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=34efaef6c103d636ab507a0cc34dca4d3aecc055","refsource":"MISC","tags":[],"title":"git.openssl.org Git - openssl.git/commitdiff","mime":"text/xml","httpstatus":"404","archivestatus":"404"},{"url":"https://www.openssl.org/news/secadv/20231106.txt","name":"https://www.openssl.org/news/secadv/20231106.txt","refsource":"MISC","tags":[],"title":"/err404.html","mime":"text/html","httpstatus":"404","archivestatus":"404"},{"url":"https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=db925ae2e65d0d925adef429afc37f75bd1c2017","name":"https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=db925ae2e65d0d925adef429afc37f75bd1c2017","refsource":"MISC","tags":[],"title":"git.openssl.org Git - openssl.git/commitdiff","mime":"text/xml","httpstatus":"200","archivestatus":"404"},{"url":"https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=710fee740904b6290fef0dd5536fbcedbc38ff0c","name":"https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=710fee740904b6290fef0dd5536fbcedbc38ff0c","refsource":"MISC","tags":[],"title":"git.openssl.org Git - openssl.git/commitdiff","mime":"text/xml","httpstatus":"404","archivestatus":"404"},{"url":"http://www.openwall.com/lists/oss-security/2023/11/06/2","name":"http://www.openwall.com/lists/oss-security/2023/11/06/2","refsource":"MISC","tags":[],"title":"oss-security - OpenSSL Security Advisory","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-5678","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-5678","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2023","cve_id":"5678","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openssl","cpe5":"openssl","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2023-5678","qid":"161251","title":"Oracle Enterprise Linux Security Update for Open Secure Sockets Layer (OpenSSL) (ELSA-2023-7877)"},{"cve":"CVE-2023-5678","qid":"161287","title":"Oracle Enterprise Linux Security Update for Open Secure Sockets Layer (OpenSSL) (ELSA-2024-12056)"},{"cve":"CVE-2023-5678","qid":"200094","title":"Ubuntu Security Notification for Open Secure Sockets Layer (OpenSSL) Vulnerabilities (USN-6622-1)"},{"cve":"CVE-2023-5678","qid":"200107","title":"Ubuntu Security Notification for Open Secure Sockets Layer (OpenSSL) Vulnerabilities (USN-6632-1)"},{"cve":"CVE-2023-5678","qid":"200215","title":"Ubuntu Security Notification for Open Secure Sockets Layer (OpenSSL) Vulnerabilities (USN-6709-1)"},{"cve":"CVE-2023-5678","qid":"242632","title":"Red Hat Update for Open Secure Sockets Layer (OpenSSL) (RHSA-2023:7877)"},{"cve":"CVE-2023-5678","qid":"242687","title":"Red Hat Update for Open Secure Sockets Layer (OpenSSL) (RHSA-2024:0154)"},{"cve":"CVE-2023-5678","qid":"242696","title":"Red Hat Update for Open Secure Sockets Layer (OpenSSL) (RHSA-2024:0208)"},{"cve":"CVE-2023-5678","qid":"243077","title":"Red Hat Update for JBoss Core Services (RHSA-2024:1316)"},{"cve":"CVE-2023-5678","qid":"330164","title":"IBM Advanced Interactive eXecutive (AIX) Open Secure Sockets Layer (OpenSSL) Multiple Vulnerabilities (openssl_advisory40)"},{"cve":"CVE-2023-5678","qid":"356767","title":"Amazon Linux Security Advisory for openssl11 : ALAS2-2023-2351"},{"cve":"CVE-2023-5678","qid":"356770","title":"Amazon Linux Security Advisory for Open Secure Sockets Layer (OpenSSL) : ALAS2-2023-2350"},{"cve":"CVE-2023-5678","qid":"356780","title":"Amazon Linux Security Advisory for Open Secure Sockets Layer (OpenSSL) : ALAS-2023-1891"},{"cve":"CVE-2023-5678","qid":"356891","title":"Amazon Linux Security Advisory for Open Secure Sockets Layer (OpenSSL)-snapsafe : ALAS2OPENSSL-SNAPSAFE-2023-004"},{"cve":"CVE-2023-5678","qid":"356903","title":"Amazon Linux Security Advisory for Open Secure Sockets Layer (OpenSSL) : ALAS2023-2023-443"},{"cve":"CVE-2023-5678","qid":"356993","title":"Amazon Linux Security Advisory for Open Secure Sockets Layer (OpenSSL) : AL2012-2023-477"},{"cve":"CVE-2023-5678","qid":"357333","title":"Amazon Linux Security Advisory for edk2 : ALAS2-2024-2502"},{"cve":"CVE-2023-5678","qid":"379545","title":"Splunk Enterprise Third Party Package Updates for March 2024 (SVD-2024-0303)"},{"cve":"CVE-2023-5678","qid":"379546","title":"Splunk Universal Forwarder Third Party Package Updates for March 2024 (SVD-2024-0304)"},{"cve":"CVE-2023-5678","qid":"379630","title":"Alibaba Cloud Linux Security Update for Open Secure Sockets Layer (OpenSSL) (ALINUX3-SA-2024:0047)"},{"cve":"CVE-2023-5678","qid":"503552","title":"Alpine Linux Security Update for Open Secure Sockets Layer (OpenSSL)"},{"cve":"CVE-2023-5678","qid":"503621","title":"Alpine Linux Security Update for Open Secure Sockets Layer (OpenSSL)"},{"cve":"CVE-2023-5678","qid":"503687","title":"Alpine Linux Security Update for Open Secure Sockets Layer (OpenSSL)"},{"cve":"CVE-2023-5678","qid":"504259","title":"Alpine Linux Security Update for openssl"},{"cve":"CVE-2023-5678","qid":"505911","title":"Alpine Linux Security Update for openssl"},{"cve":"CVE-2023-5678","qid":"673338","title":"EulerOS Security Update for shim (EulerOS-SA-2024-1098)"},{"cve":"CVE-2023-5678","qid":"673343","title":"EulerOS Security Update for Open Secure Sockets Layer (OpenSSL) (EulerOS-SA-2024-1125)"},{"cve":"CVE-2023-5678","qid":"673443","title":"EulerOS Security Update for Open Secure Sockets Layer (OpenSSL) (EulerOS-SA-2024-1069)"},{"cve":"CVE-2023-5678","qid":"673480","title":"EulerOS Security Update for shim (EulerOS-SA-2024-1129)"},{"cve":"CVE-2023-5678","qid":"673598","title":"EulerOS Security Update for compat-openssl10 (EulerOS-SA-2024-1258)"},{"cve":"CVE-2023-5678","qid":"673684","title":"EulerOS Security Update for shim (EulerOS-SA-2024-1164)"},{"cve":"CVE-2023-5678","qid":"673687","title":"EulerOS Security Update for Open Secure Sockets Layer (OpenSSL) (EulerOS-SA-2024-1184)"},{"cve":"CVE-2023-5678","qid":"673724","title":"EulerOS Security Update for shim (EulerOS-SA-2024-1299)"},{"cve":"CVE-2023-5678","qid":"673737","title":"EulerOS Security Update for Open Secure Sockets Layer (OpenSSL) (EulerOS-SA-2024-1287)"},{"cve":"CVE-2023-5678","qid":"673773","title":"EulerOS Security Update for linux-sgx (EulerOS-SA-2024-1124)"},{"cve":"CVE-2023-5678","qid":"673790","title":"EulerOS Security Update for shim (EulerOS-SA-2024-1186)"},{"cve":"CVE-2023-5678","qid":"673797","title":"EulerOS Security Update for shim-signed (EulerOS-SA-2024-1165)"},{"cve":"CVE-2023-5678","qid":"673858","title":"EulerOS Security Update for openssl111d (EulerOS-SA-2024-1157)"},{"cve":"CVE-2023-5678","qid":"673889","title":"EulerOS Security Update for shim (EulerOS-SA-2024-1113)"},{"cve":"CVE-2023-5678","qid":"673908","title":"EulerOS Security Update for shim (EulerOS-SA-2024-1206)"},{"cve":"CVE-2023-5678","qid":"673915","title":"EulerOS Security Update for Open Secure Sockets Layer (OpenSSL) (EulerOS-SA-2024-1155)"},{"cve":"CVE-2023-5678","qid":"673962","title":"EulerOS Security Update for Open Secure Sockets Layer (OpenSSL) (EulerOS-SA-2024-1204)"},{"cve":"CVE-2023-5678","qid":"674007","title":"EulerOS Security Update for Open Secure Sockets Layer (OpenSSL) (EulerOS-SA-2024-1093)"},{"cve":"CVE-2023-5678","qid":"674055","title":"EulerOS Security Update for Open Secure Sockets Layer (OpenSSL) (EulerOS-SA-2024-1109)"},{"cve":"CVE-2023-5678","qid":"674097","title":"EulerOS Security Update for shim (EulerOS-SA-2024-1074)"},{"cve":"CVE-2023-5678","qid":"691351","title":"Free Berkeley Software Distribution (FreeBSD) Security Update for Open Secure Sockets Layer (OpenSSL) (a5956603-7e4f-11ee-9df6-84a93843eb75)"},{"cve":"CVE-2023-5678","qid":"755307","title":"SUSE Enterprise Linux Security Update for openssl-1_1 (SUSE-SU-2023:4524-1)"},{"cve":"CVE-2023-5678","qid":"755308","title":"SUSE Enterprise Linux Security Update for openssl-1_0_0 (SUSE-SU-2023:4523-1)"},{"cve":"CVE-2023-5678","qid":"755309","title":"SUSE Enterprise Linux Security Update for openssl-1_0_0 (SUSE-SU-2023:4522-1)"},{"cve":"CVE-2023-5678","qid":"755310","title":"SUSE Enterprise Linux Security Update for openssl-1_1 (SUSE-SU-2023:4521-1)"},{"cve":"CVE-2023-5678","qid":"755311","title":"SUSE Enterprise Linux Security Update for openssl-1_1 (SUSE-SU-2023:4520-1)"},{"cve":"CVE-2023-5678","qid":"755312","title":"SUSE Enterprise Linux Security Update for openssl-1_1 (SUSE-SU-2023:4519-1)"},{"cve":"CVE-2023-5678","qid":"755313","title":"SUSE Enterprise Linux Security Update for openssl-1_1 (SUSE-SU-2023:4518-1)"},{"cve":"CVE-2023-5678","qid":"755361","title":"SUSE Enterprise Linux Security Update for compat-openssl098 (SUSE-SU-2023:4593-1)"},{"cve":"CVE-2023-5678","qid":"755375","title":"SUSE Enterprise Linux Security Update for openssl-3 (SUSE-SU-2023:4635-1)"},{"cve":"CVE-2023-5678","qid":"755461","title":"SUSE Enterprise Linux Security Update for openssl-3 (SUSE-SU-2023:4649-1)"},{"cve":"CVE-2023-5678","qid":"755503","title":"SUSE Enterprise Linux Security Update for openssl-1_1-livepatches (SUSE-SU-2023:4919-1)"},{"cve":"CVE-2023-5678","qid":"755504","title":"SUSE Enterprise Linux Security Update for Open Secure Sockets Layer (OpenSSL)-1_1-livepatches (SUSE-SU-2023:4918-1)"},{"cve":"CVE-2023-5678","qid":"907698","title":"Common Base Linux Mariner (CBL-Mariner) Security Update for Open Secure Sockets Layer (OpenSSL) (31880-1)"},{"cve":"CVE-2023-5678","qid":"907730","title":"Common Base Linux Mariner (CBL-Mariner) Security Update for edk2 (31872-1)"},{"cve":"CVE-2023-5678","qid":"941507","title":"AlmaLinux Security Update for Open Secure Sockets Layer (OpenSSL) (ALSA-2023:7877)"}]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2023-5678","ASSIGNER":"openssl-security@openssl.org","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"Issue summary: Generating excessively long X9.42 DH keys or checking\nexcessively long X9.42 DH keys or parameters may be very slow.\n\nImpact summary: Applications that use the functions DH_generate_key() to\ngenerate an X9.42 DH key may experience long delays.  Likewise, applications\nthat use DH_check_pub_key(), DH_check_pub_key_ex() or EVP_PKEY_public_check()\nto check an X9.42 DH key or X9.42 DH parameters may experience long delays.\nWhere the key or parameters that are being checked have been obtained from\nan untrusted source this may lead to a Denial of Service.\n\nWhile DH_check() performs all the necessary checks (as of CVE-2023-3817),\nDH_check_pub_key() doesn't make any of these checks, and is therefore\nvulnerable for excessively large P and Q parameters.\n\nLikewise, while DH_generate_key() performs a check for an excessively large\nP, it doesn't check for an excessively large Q.\n\nAn application that calls DH_generate_key() or DH_check_pub_key() and\nsupplies a key or parameters obtained from an untrusted source could be\nvulnerable to a Denial of Service attack.\n\nDH_generate_key() and DH_check_pub_key() are also called by a number of\nother OpenSSL functions.  An application calling any of those other\nfunctions may similarly be affected.  The other functions affected by this\nare DH_check_pub_key_ex(), EVP_PKEY_public_check(), and EVP_PKEY_generate().\n\nAlso vulnerable are the OpenSSL pkey command line application when using the\n\"-pubcheck\" option, as well as the OpenSSL genpkey command line application.\n\nThe OpenSSL SSL/TLS implementation is not affected by this issue.\n\nThe OpenSSL 3.0 and 3.1 FIPS providers are not affected by this issue.\n\n"}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Excessive Iteration"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"OpenSSL","product":{"product_data":[{"product_name":"OpenSSL","version":{"version_data":[{"version_affected":"<","version_name":"1.0.2","version_value":"1.0.2zj"},{"version_affected":"<","version_name":"1.1.1","version_value":"1.1.1x"},{"version_affected":"<","version_name":"3.0.0","version_value":"3.0.13"},{"version_affected":"<","version_name":"3.1.0","version_value":"3.1.5"}]}}]}}]}},"references":{"reference_data":[{"url":"https://www.openssl.org/news/secadv/20231106.txt","refsource":"MISC","name":"https://www.openssl.org/news/secadv/20231106.txt"},{"url":"https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=34efaef6c103d636ab507a0cc34dca4d3aecc055","refsource":"MISC","name":"https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=34efaef6c103d636ab507a0cc34dca4d3aecc055"},{"url":"https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=710fee740904b6290fef0dd5536fbcedbc38ff0c","refsource":"MISC","name":"https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=710fee740904b6290fef0dd5536fbcedbc38ff0c"},{"url":"https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=db925ae2e65d0d925adef429afc37f75bd1c2017","refsource":"MISC","name":"https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=db925ae2e65d0d925adef429afc37f75bd1c2017"},{"url":"https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=ddeb4b6c6d527e54ce9a99cba785c0f7776e54b6","refsource":"MISC","name":"https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=ddeb4b6c6d527e54ce9a99cba785c0f7776e54b6"}]},"generator":{"engine":"Vulnogram 0.1.0-dev"},"source":{"discovery":"UNKNOWN"},"credits":[{"lang":"en","value":"David Benjamin (Google)"},{"lang":"en","value":"Richard Levitte"}]},"nvd":{"publishedDate":"2023-11-06 16:15:00","lastModifiedDate":"2023-11-30 22:15:00","problem_types":["CWE-754"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM"},"exploitabilityScore":3.9,"impactScore":1.4}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*","versionStartIncluding":"1.0.2","versionEndExcluding":"1.0.2zj","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*","versionStartIncluding":"1.1.1","versionEndExcluding":"1.1.1x","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*","versionStartIncluding":"3.0.0","versionEndExcluding":"3.0.13","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*","versionStartIncluding":"3.1.0","versionEndExcluding":"3.1.5","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}