OpenSSL 1.1.1g has been released to address a vulnerability related to TLS 1.3

Available maintenance release of the cryptographic library OpenSSL 1.1.1g, which addresses vulnerability (CVE-2020-1967), leading to a denial of service when trying to negotiate a TLS 1.3 connection with a maliciously controlled server or client. The vulnerability has been assigned a high severity level.

The issue only occurs in applications using the SSL_check_chain() function, resulting in a process crash when TLS extension "signature_algorithms_cert" is misused. Specifically, receiving an unsupported or incorrect value for the digital signature algorithm during the connection negotiation causes a null pointer dereference and a process crash. The problem manifests starting from OpenSSL version 1.1.1d.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster