Junglewise Threat Intelligence

CVE-2018-1000808: PYSEC-2018-24 - Python Cryptographic Authority pyopenssl version Before 17.5.0 contains a CWE - 401 : Failure to Release Memory Before Removing Last Referen

CVE-2018-1000808 · Severity: low · CVSS 3 · Published 2018-10-08

Technologies: pyopenssl (PyPI). Vendors: PyPI.

Executive brief

pyOpenSSL is a Python cryptography library used by applications to manage SSL/TLS certificates and cryptographic keys. The library incorrectly managed memory when processing PKCS #12 certificate stores, causing memory leaks and potential use-after-free conditions. An attacker could trigger this vulnerability by initiating a TLS connection that causes an application to reload certificates, leading to resource exhaustion and denial of service.

Technical details

The vulnerability is a memory management error (CWE-401, CWE-404) in pyOpenSSL's handling of PKCS #12 stores. The root cause involves two separate issues: (1) a memory leak where PKCS #12 objects with CA certificates freed the stack but not the underlying X.509 objects, and (2) a potential use-after-free condition in callback handling where X509 objects were created without owning their own memory. The attack is network-reachable and requires no authentication or user interaction—a remote attacker can trigger the vulnerability by initiating a TLS connection that causes the target application to reload certificates from a PKCS #12 store. Successful exploitation results in resource exhaustion and denial of service. The vulnerability was fixed in pyOpenSSL version 17.5.0.

Affected products

  • pyca pyOpenSSL before 17.5.0

Timeline

  • 2018-10-08: disclosed
  • 2017-11-30: patched: Fix merged in PR #723
  • 2018-10-10: advisory

References

Related threats