Buffer overflow in OpenSSL, exploited when checking X.509 certificates.

A corrective release of the cryptographic library OpenSSL 3.0.7 has been published, addressing two vulnerabilities. Both issues are caused by a buffer overflow in the email field validation code in X.509 certificates and could potentially lead to code execution when processing a specially crafted certificate. At the time of the fix’s publication, no working exploit capable of executing code had been reported by the OpenSSL developers.

Although the prior announcement of the new release mentioned a critical issue, the vulnerability's status in the released update was actually lowered to that of serious but non-critical. According to the project's established rules, the severity level is reduced if the issue manifests in atypical configurations or if there is a low probability of practical exploitation.

In this case, the severity level was lowered as a detailed analysis of the vulnerability by several organizations concluded that the possibility of code execution during exploitation is blocked by the protection mechanisms against stack overflow used in many platforms. Additionally, the network layout used in some Linux distributions causes the out-of-bounds 4 bytes to overlap with the subsequent unused buffer in the stack. However, it is not excluded that there are platforms where exploitation for code execution is possible.

Identified issues:

  • CVE-2022-3602 — initially presented as critical, leads to a 4-byte buffer overflow when checking the specially crafted email field in an X.509 certificate. In the TLS client, the vulnerability can be exploited when connecting to server, controlled by the attacker. On the TLS server, the vulnerability can be exploited if client authentication using certificates is employed. The vulnerability manifests at the stage after the verification of the certificate chain of trust, meaning that an attacker must have a certificate issued by a compromised certificate authority.
  • CVE-2022-3786 — another exploitation vector for the CVE-2022-3602 vulnerability identified during the issue analysis. The differences relate to the ability to overflow the stack buffer by an arbitrary number of bytes containing the character ‘.’ (i.e., the attacker cannot control the overflow contents, and the problem can only be used to trigger an application crash).

The vulnerabilities manifest only in the OpenSSL 3.0.x branch (the error was introduced in the Unicode (punycode) conversion code added to the 3.0.x branch). Releases of OpenSSL 1.1.1, as well as forks from OpenSSL, such as LibreSSL and BoringSSL, are not affected by this issue. At the same time, an update to OpenSSL 1.1.1s has been released, which includes only non-security related bug fixes.

The OpenSSL 3.0 branch is used in distributions such as Ubuntu 22.04, CentOS Stream 9, RHEL 9, OpenMandriva 4.2, Gentoo, Fedora 36, and Debian Testing/Unstable. Users of these systems are advised to install updates as soon as possible (Debian, Ubuntu, RHEL, SUSE/openSUSE, Fedora, Arch). In SUSE Linux Enterprise 15 SP4 and openSUSE Leap 15.4, packages with OpenSSL 3.0 are available optionally, while system packages use the 1.1.1 branch. The following distributions remain on the OpenSSL 1.x branches: Debian 11, Arch Linux, Void Linux, Ubuntu 20.04, Slackware, ALT Linux, RHEL 8, OpenWrt, Alpine Linux 3.16, and FreeBSD.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster