openssl is vulnerable to NULL Pointer Dereference
55
Medium Risk
CMP password based MAC verification reads the protectionAlg parameter and, when the pointer is not NULL, casts it to a PBM parameter without checking the ASN.1 type. A message whose parameter has a different type makes that cast follow an invalid pointer and crashes a CMP server that accepts password based protection, or a CMP client checking a response. The fix checks the parameter type before it uses the value.
You are affected if you are using a version that falls within the vulnerable range and your application uses CMP with password based message protection.
openssl is vulnerable to NULL Pointer Dereference in versions 3.0.0 - 3.0.21, 3.4.0 - 3.4.6, 3.5.0 - 3.5.7, 3.6.0 - 3.6.3 and 4.0.0 - 4.0.1.
Upgrade the openssl library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.