CVE-2020-1967
openssl - security update
Description
Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signature_algorithms_cert" TLS extension. The crash occurs if an invalid or unrecognised signature algorithm is received from the peer. This could be exploited by a malicious peer in a Denial of Service attack. OpenSSL version 1.1.1d, 1.1.1e, and 1.1.1f are affected by this issue. This issue did not affect OpenSSL versions prior to 1.1.1d. Fixed in OpenSSL 1.1.1g (Affected 1.1.1d-1.1.1f).
How to fix CVE-2020-1967
To remediate CVE-2020-1967, upgrade the affected package to a fixed version below.
- —upgrade to 1.1.1g-r0 or later
- —upgrade to 1.1.1g-r0 or later
Is CVE-2020-1967 being exploited?
Likely — EPSS is 53.3%, placing CVE-2020-1967 in the top tier of vulnerabilities by exploitation probability. Prioritise patching.
Affected packages (2)
- >= 1.1.1d, < 1.1.1g-r0
- from 0, < 1.1.1g-r0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |