Executive brief
OpenSSL is a widely used security library that enables encrypted communications for websites and applications. A vulnerability in how it verifies digital certificates can cause an application to crash when it encounters a specially crafted certificate. This could allow an attacker to disrupt services or take down applications that rely on OpenSSL for secure connections.
Technical details
A type confusion vulnerability exists in OpenSSL's certificate name checking logic. When an application (typically a TLS client) validates a certificate and specifies an expected DNS name, IP address, or email, OpenSSL may incorrectly handle the 'otherName' field in the Subject Alternative Name (SAN) extension. Specifically, the code may attempt to access a union member in the GENERAL_NAME structure that does not match the actual type, leading to an invalid memory read and a segmentation fault. This issue affects OpenSSL versions 3.0 through 3.3, but does not impact the FIPS modules. Patches are available in versions 3.0.15, 3.1.7, 3.2.3, and 3.3.2.
Affected products
- OpenSSL OpenSSL 3.0.0 to 3.0.14, 3.1.0 to 3.1.6, 3.2.0 to 3.2.2, 3.3.0 to 3.3.1
Timeline
- 2024-09-03: advisory: OpenSSL security advisory published
- 2024-09-03: patched: Fixes committed to OpenSSL repository
References
- https://github.com/openssl/openssl/commit/05f360d9e849a1b277db628f1f13083a7f8dd04f
- https://github.com/openssl/openssl/commit/06d1dc3fa96a2ba5a3e22735a033012aadc9f0d6
- https://github.com/openssl/openssl/commit/621f3729831b05ee828a3203eddb621d014ff2b2
- https://github.com/openssl/openssl/commit/7dfcee2cd2a63b2c64b9b4b0850be64cb695b0a0
- https://openssl-library.org/news/secadv/20240903.txt
- http://www.openwall.com/lists/oss-security/2024/09/03/4
- https://lists.freebsd.org/archives/freebsd-security/2024-September/000303.html