Vulnerability in OpenSSL and LibreSSL leading to looping when processing invalid certificates

Corrective releases of the OpenSSL cryptographic library 3.0.2 and 1.1.1n are available. The update resolves a vulnerability (CVE-2022-0778) that can be exploited to cause a denial of service (infinite loop in the handler). The vulnerability can be triggered by processing a specially crafted certificate. The issue occurs in both server-side and client-side applications that can handle user-provided certificates.

The problem is caused by an error in the BN_mod_sqrt() function, which leads to an infinite loop when calculating the square root modulo a number that is not prime. This function is applied during the parsing of certificates with keys based on elliptic curves. Exploitation involves substituting incorrect parameters into the elliptic curve in the certificate. Since the problem occurs before the digital signature of the certificate is verified, an unauthenticated user can conduct the attack by causing a client or server certificate to be passed to applications using OpenSSL.

The vulnerability also affects the LibreSSL library developed by the OpenBSD project, with a fix proposed in the LibreSSL 3.3.6, 3.4.3, and 3.5.1 corrective releases. Additionally, a breakdown of the conditions for exploiting the vulnerability has been published (an example of a malicious certificate that causes a hang has not yet been publicly released).

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster