🛡️ MGASA-2023-0130 — openssl

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Updated openssl packages fix security vulnerability

A read buffer overrun can be triggered in X.509 certificate verification,

specifically in name constraint checking. Note that this occurs after

certificate chain signature verification and requires either a CA to have

signed the malicious certificate or for the application to continue

certificate verification despite failure to construct a path to a trusted

issuer. The read buffer overrun might result in a crash which could lead

to a denial of service attack. In theory it could also result in the

disclosure of private memory contents (such as private keys, or sensitive

plaintext) although we are not aware of any working exploit leading to

memory contents disclosure as of the time of release of this advisory. In

a TLS client, this can be triggered by connecting to a malicious server.

In a TLS server, this can be triggered if the server requests client

authentication and a malicious client connects. (CVE-2022-4203)

A timing based side channel exists in the OpenSSL RSA Decryption

implementation which could be sufficient to recover a plaintext across a

network in a Bleichenbacher style attack. To achieve a successful

decryption an attacker would have to be able to send a very large number

of trial messages for decryption. The vulnerability affects all RSA

padding modes: PKCS#1 v1.5, RSA-OEAP and RSASVE. For example, in a TLS

connection, RSA is commonly used by a client to send an encrypted

pre-master secret to the server. An attacker that had observed a genuine

connection between a client and a server could use this flaw to send trial

messages to the server and record the time taken to process them. After a

sufficiently large number of messages the attacker could recover the

pre-master secret used for the original connection and thus be able to

decrypt the application data sent over that connection. (CVE-2022-4304)

The function PEM_read_bio_ex() reads a PEM file from a BIO and parses and

decodes the "name" (e.g. "CERTIFICATE"), any header data and the payload

data. If the function succeeds then the "name_out", "header" and "data"

arguments are populated with pointers to buffers containing the relevant

decoded data. The caller is responsible for freeing those buffers. It is

possible to construct a PEM file that results in 0 bytes of payload data.

In this case PEM_read_bio_ex() will return a failure code but will

populate the header argument with a pointer to a buffer that has already

been freed. If the caller also frees this buffer then a double free will

occur. This will most likely lead to a crash. This could be exploited by

an attacker who has the ability to supply malicious PEM files for parsing

to achieve a denial of service attack. The functions PEM_read_bio() and

PEM_read() are simple wrappers around PEM_read_bio_ex() and therefore

these functions are also directly affected. These functions are also

called indirectly by a number of other OpenSSL functions including

PEM_X509_INFO_read_bio_ex() and SSL_CTX_use_serverinfo_file() which are

also vulnerable. Some OpenSSL internal uses of these functions are not

vulnerable because the caller does not free the header argument if

PEM_read_bio_ex() returns a failure code. These locations include the

PEM_read_bio_TYPE() functions as well as the decoders introduced in

OpenSSL 3.0. The OpenSSL asn1parse command line application is also

impacted by this issue. (CVE-2022-4450)

The public API function BIO_new_NDEF is a helper function used for

streaming ASN.1 data via a BIO. It is primarily used internally to OpenSSL

to support the SMIME, CMS and PKCS7 streaming capabilities, but may also

be called directly by end user applications. The function receives a BIO

from the caller, prepends a new BIO_f_asn1 filter BIO onto the front of it

to form a BIO chain, and then returns the new head of the BIO chain to the

caller. Under certain conditions, for example if a CMS recipient public

key is invalid, the new filter BIO is freed and the function returns a

NULL result indicating a failure. However, in this case, the BIO chain is

not properly cleaned up and the BIO passed by the caller still retains

internal pointers to the previously freed filter BIO. If the caller then

goes on to call BIO_pop() on the BIO then a use-after-free will occur.

This will most likely result in a crash. This scenario occurs directly in

the internal function B64_write_ASN1() which may cause BIO_new_NDEF() to

be called and will subsequently call BIO_pop() on the BIO. This internal

function is in turn called by the public API functions

PEM_write_bio_ASN1_stream, PEM_write_bio_CMS_stream,

PEM_write_bio_PKCS7_stream, SMIME_write_ASN1, SMIME_write_CMS and

SMIME_write_PKCS7. Other public API functions that may be impacted by this

include i2d_ASN1_bio_stream, BIO_new_CMS, BIO_new_PKCS7,

i2d_CMS_bio_stream and i2d_PKCS7_bio_stream. The OpenSSL cms and smime

command line applications are similarly affected. (CVE-2023-0215)

An invalid pointer dereference on

Affected software

MGASA-2023-0130 is recorded against 1 package.

  • openssl (fixed in 1.1.1t-1.mga8)

Timeline and source

Published on 11 April 2023 and last revised on 16 April 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

advisories.mageia.org (Advisory)
bugs.mageia.org (Report)
www.openssl.org (Web)
www.debian.org (Web)
ubuntu.com (Advisory)
lists.fedoraproject.org (Web)
lists.fedoraproject.org (Web)
access.redhat.com (Web)
www.openssl.org (Web)
www.openssl.org (Web)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2023-04-11
Updated 2026-08-12
Modified 2026-04-16
Fix URL N/A

Affected Packages

Software From version Fixed in
openssl 1.1.1t-1.mga8

Free Vulnerability Check

Is your site affected by MGASA-2023-0130?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against MGASA-2023-0130 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.