NULL pointer dereference in OpenSSL - CVE-2023-0217

 

NULL pointer dereference in OpenSSL - CVE-2023-0217

Published: February 7, 2023 / Updated: March 8, 2023


Vulnerability identifier: #VU71998
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-0217
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a NULL pointer dereference error when validating the DSA public key. A remote attacker can pass specially crafted data to the application and perform a denial of service (DoS) attack.


Affected software

OpenSSL
IBM Business Automation Workflow
IBM Observability with Instana
IBM Rational Build Forge
IBM MQ
IBM QRadar WinCollect Agent
Tenable Nessus
IBM Integration Bus
IBM Spectrum Copy Data Management
IBM Spectrum Conductor
IBM MaaS360 Mobile Enterprise Gateway
IBM MaaS360 Cloud Extender Agent
IBM Tivoli Netcool System Service Monitors/Application Service Monitors
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Spectrum Control
App Connect Enterprise Certified Container
IBM Spectrum Symphony
IBM Rational ClearQuest
IBM Spectrum Protect Plus
Juniper Cloud Native Router
PCULogger tool
Junos cRPD
PCU400
SCALANCE XC216-4C
SCALANCE XF204
SCALANCE XC224-4C G EEC
SCALANCE XC224-4C G
SCALANCE XC224
SCALANCE XC216EEC
SCALANCE XC216-4C G EEC
SCALANCE XC216-4C G
SCALANCE XF204 DNA
SCALANCE XC216-3G PoE
SCALANCE XC216
SCALANCE XC208G PoE
SCALANCE XC208G EEC
SCALANCE XC208G
SCALANCE XC208EEC
SCALANCE XC208
SCALANCE XC206-2SFP G
SCALANCE XF204-2BA
SIPLUS NET SCALANCE XC216-4C
SIPLUS NET SCALANCE XC208
SIPLUS NET SCALANCE XC206-2SFP
SCALANCE XF204-2BA DNA
SCALANCE XP208
SCALANCE XC206-2SFP G EEC
SCALANCE XP208EEC
SCALANCE XP208PoE EEC
SIPLUS NET SCALANCE XC206-2
SCALANCE XR328-4C WG
SCALANCE XR326-2C PoE WG
SCALANCE XR324WG
SCALANCE XP216POE EEC
SCALANCE XP216EEC
SCALANCE XP216
SCALANCE XC206-2SFP EEC
SCALANCE XC206-2SFP
SCALANCE XC206-2G PoE EEC
SCALANCE XC206-2G PoE
SCALANCE XC206-2
SCALANCE XB216
SCALANCE XB213-3LD
SCALANCE XB213-3
SCALANCE XB208
SCALANCE XB205-3LD
SCALANCE XB205-3
Amazon Linux AMI
Gentoo Linux
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Manager Server
IBM AIX
Fedora
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Oracle Solaris
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Desktop
openSUSE Leap
Ubuntu
Junos OS Evolved
MobileFirst Platform
librdkafka
Dell Hybrid Client
cflinuxfs3
Aspera faspio Gateway
Dell EMC Streaming Data Platform
IBM MaaS360 Base Module
MaaS360 PKI Certificate Module
MaaS360 Configuration Utility
Platform Automation Toolkit
IBM Spectrum Protect Client Management Service
Cognos Transformer
Dell Data Protection Central
API Manager
IBM Integrated Analytics System
API Gateway
IBM VIOS
Nessus Network Monitor
Red Hat OpenShift Container Platform
Tenable.sc
Barracuda CloudGen WAN
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libssl1.1 (Ubuntu package)
openssl (Red Hat package)
openssl-3-debugsource
libopenssl-3-devel
libopenssl3
libopenssl3-debuginfo
openssl-3
openssl-3-doc
libopenssl3-32bit-debuginfo
libopenssl3-32bit
libopenssl-3-devel-32bit
openssl-3-debuginfo
libssl3 (Ubuntu package)
openssl
openssl3
dev-libs/openssl
Nessus Agent
IBM App Connect Enterprise
Node.js
IBM MaaS360 VPN Module

How to mitigate CVE-2023-0217

Install updates from vendor's website.

OpenSSL - update to 3.0.8
PCULogger tool - update to 1.2.0
PCU400 - addressed in versions 6.6.0, 9.4.2
API Manager - update to February 2023
API Gateway - update to February 2023
librdkafka - update to 2.1.0
Nessus Network Monitor - update to 6.2.1
Tenable.sc - update to 6.0.0 Patch SC-202303.1-6
IBM Rational Build Forge - update to 8.0.0.24
Barracuda CloudGen WAN - update to 8.3.1 1093
IBM MQ - addressed in versions 9.0.0.17, 9.2.0.11, 9.3.0.5
Nessus Agent - update to 10.3.2
IBM QRadar WinCollect Agent - update to 10.1.3
Tenable Nessus - addressed in versions 10.4.3, 10.5.0
Node.js - addressed in versions 14.21.3, 16.19.1, 18.14.1, 19.6.1
Junos OS Evolved - addressed in versions 22.1R3-S5-EVO, 22.2R3-S3-EVO, 22.3R3-S2-EVO, 22.4R3-S1-EVO, 23.2R2-EVO, 23.4R1-EVO
cflinuxfs3 - update to 0.351.0
IBM Integrated Analytics System - update to 1.0.30.0
libssl1.1 (Ubuntu package) - addressed in versions 1.1.1f-1ubuntu2.17, 1.1.1-1ubuntu2.1~18.04.21
Aspera faspio Gateway - update to 1.3.2
Dell EMC Streaming Data Platform - update to 1.7.0
IBM Spectrum Copy Data Management - update to 2.2.20.0
IBM Spectrum Conductor - update to 2.5.1 FP2
openssl (Red Hat package) - addressed in versions 3.0.1-46.el9_0, 3.0.1-47.el9_1
openssl-3-debugsource - update to 3.0.1-150400.4.17.1
libopenssl-3-devel - update to 3.0.1-150400.4.17.1
libopenssl3 - update to 3.0.1-150400.4.17.1
libopenssl3-debuginfo - update to 3.0.1-150400.4.17.1
openssl-3 - update to 3.0.1-150400.4.17.1
openssl-3-doc - update to 3.0.1-150400.4.17.1
libopenssl3-32bit-debuginfo - update to 3.0.1-150400.4.17.1
libopenssl3-32bit - update to 3.0.1-150400.4.17.1
libopenssl-3-devel-32bit - update to 3.0.1-150400.4.17.1
openssl-3-debuginfo - update to 3.0.1-150400.4.17.1
libssl3 (Ubuntu package) - addressed in versions 3.0.2-0ubuntu1.8, 3.0.5-2ubuntu2.1
openssl - update to 3.0.5-1
openssl3 - update to 3.0.7-5.el8.1
openssl - addressed in versions 3.0.8-1.fc36, 3.0.8-1.fc37
dev-libs/openssl - update to 3.0.10
IBM MaaS360 Base Module - update to 3.000.100
MaaS360 PKI Certificate Module - update to 3.000.100
MaaS360 Configuration Utility - update to 3.000.100
IBM MaaS360 VPN Module - update to 3.000.100
IBM MaaS360 Mobile Enterprise Gateway - update to 3.000.100
IBM MaaS360 Cloud Extender Agent - update to 3.000.100.069
IBM Tivoli Netcool System Service Monitors/Application Service Monitors - update to 4.0.1 SP11
Platform Automation Toolkit - addressed in versions 4.4.31, 5.0.24, 5.1.0
SCALANCE XC216-4C - update to 4.5
SCALANCE XF204 - update to 4.5
SCALANCE XC224-4C G EEC - update to 4.5
SCALANCE XC224-4C G - update to 4.5
SCALANCE XC224 - update to 4.5
SCALANCE XC216EEC - update to 4.5
SCALANCE XC216-4C G EEC - update to 4.5
SCALANCE XC216-4C G - update to 4.5
SCALANCE XF204 DNA - update to 4.5
SCALANCE XC216-3G PoE - update to 4.5
SCALANCE XC216 - update to 4.5
SCALANCE XC208G PoE - update to 4.5
SCALANCE XC208G EEC - update to 4.5
SCALANCE XC208G - update to 4.5
SCALANCE XC208EEC - update to 4.5
SCALANCE XC208 - update to 4.5
SCALANCE XC206-2SFP G - update to 4.5
SCALANCE XF204-2BA - update to 4.5
SIPLUS NET SCALANCE XC216-4C - update to 4.5
SIPLUS NET SCALANCE XC208 - update to 4.5
SIPLUS NET SCALANCE XC206-2SFP - update to 4.5
SCALANCE XF204-2BA DNA - update to 4.5
SCALANCE XP208 - update to 4.5
SCALANCE XC206-2SFP G EEC - update to 4.5
SCALANCE XP208EEC - update to 4.5
SCALANCE XP208PoE EEC - update to 4.5
SIPLUS NET SCALANCE XC206-2 - update to 4.5
SCALANCE XR328-4C WG - update to 4.5
SCALANCE XR326-2C PoE WG - update to 4.5
SCALANCE XR324WG - update to 4.5
SCALANCE XP216POE EEC - update to 4.5
SCALANCE XP216EEC - update to 4.5
SCALANCE XP216 - update to 4.5
SCALANCE XC206-2SFP EEC - update to 4.5
SCALANCE XC206-2SFP - update to 4.5
SCALANCE XC206-2G PoE EEC - update to 4.5
SCALANCE XC206-2G PoE - update to 4.5
SCALANCE XC206-2 - update to 4.5
SCALANCE XB216 - update to 4.5
SCALANCE XB213-3LD - update to 4.5
SCALANCE XB213-3 - update to 4.5
SCALANCE XB208 - update to 4.5
SCALANCE XB205-3LD - update to 4.5
SCALANCE XB205-3 - update to 4.5
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.5
Red Hat OpenShift Container Platform - update to 4.13.0
IBM Spectrum Control - update to 5.4.10.1
App Connect Enterprise Certified Container - update to 7.0.0
IBM Spectrum Symphony - update to 7.3.2 Fix 601711
IBM Spectrum Protect Client Management Service - update to 8.1.17.2
IBM Rational ClearQuest - addressed in versions 9.0.2.8, 9.1.0.5, 10.0.3
IBM Spectrum Protect Plus - update to 10.1.14
Cognos Transformer - update to 11.1.7 Fix Pack 8
Dell Data Protection Central - update to 19.11.0-2
Junos cRPD - update to 23.4R1
Juniper Cloud Native Router - update to 23.4R1

External References

Related Security Bulletins