SB2020042175 - NULL pointer dereference in openssl (Alpine package)
Published: April 21, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) NULL pointer dereference (CVE-ID: CVE-2020-1967)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error within the SSL_check_chain() function during or after a TLS 1.3 handshake. A remote attacker can send an invalid or unrecognised signature algorithm and perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=11ace5cb8b9c94ef9fcca23e4b0401d06c7e399c
- https://git.alpinelinux.org/aports/commit/?id=9919f140cf7d3ff305dda398a2a2605489202e60
- https://git.alpinelinux.org/aports/commit/?id=e54b51b1d389ed731a8bce1f0a24c45820619dbd
- https://git.alpinelinux.org/aports/commit/?id=8d308c15ed58152196218b079d66720ad606405a