CVE-2020-1967
openssl - security update
7.5
HIGH
CVSS 3.1
EPSS 53.3%
描述
Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signature_algorithms_cert" TLS extension. The crash occurs if an invalid or unrecognised signature algorithm is received from the peer. This could be exploited by a malicious peer in a Denial of Service attack. OpenSSL version 1.1.1d, 1.1.1e, and 1.1.1f are affected by this issue. This issue did not affect OpenSSL versions prior to 1.1.1d. Fixed in OpenSSL 1.1.1g (Affected 1.1.1d-1.1.1f).
如何修補 CVE-2020-1967
要修補 CVE-2020-1967,請將受影響套件升級到下列已修補版本。
- —升級至 1.1.1g-r0 或更新版本
- —升級至 1.1.1g-r0 或更新版本
CVE-2020-1967 正在被利用嗎?
可能 — EPSS 為 53.3%,屬於高被利用機率區間,建議優先修補。
受影響套件(2)
- >= 1.1.1d, < 1.1.1g-r0
- from 0, < 1.1.1g-r0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |