openssl is vulnerable to NULL Pointer Dereference
37
Low Risk
OpenSSL selects a signature algorithm for a raw public key configuration from the peer signature_algorithms_cert extension. When only a private key is configured and no certificate is attached, that selection reads a missing certificate pointer and aborts the process. The fix requires a certificate before it reads that pointer.
You are affected if you are using a version that falls within the vulnerable range and you enable raw public keys with a private key and no certificate.
openssl is vulnerable to NULL Pointer Dereference in versions 3.4.0 - 3.4.6, 3.5.0 - 3.5.7, 3.6.0 - 3.6.3 and 4.0.0 - 4.0.1.
Upgrade the openssl library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.