QID 38917

QID 38917: OpenSSL OpenSSL Security Update

The OpenSSL Project is an Open Source toolkit implementing the Secure Sockets Layer (SSL v2/v3) and Transport Layer Security (TLS) protocols as well as a general-purpose cryptography library.

Applications that use the function EVP_PKEY_public_check() to check RSA public keys may experience long delays. Where the key that is being checked has been obtained from an untrusted source this may lead to a Denial of Service.

Affected Versions:
From 3.0.0 and before 3.0.13.
From 3.1.0 and before 3.1.5.
From 3.2.0 and before 3.2.1.

Successful exploitation of this vulnerability may allow a remote attacker to cause Denial of Service.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Please refer OpenSSL Advisory to obtain more information.
    Vendor References

    CVEs related to QID 38917

    Software Advisories
    Advisory ID Software Component Link
    OpenSSL Advisory URL Logo www.openssl.org/news/secadv/20240115.txt