Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signature_algorithms_cert" TLS extension. The crash occurs if an invalid or unrecognised signature algorithm is received from the peer. This could be exploited by a malicious peer in a Denial of Service attack. OpenSSL version 1.1.1d, 1.1.1e, and 1.1.1f are affected by this issue. This issue did not affect OpenSSL versions prior to 1.1.1d. Fixed in OpenSSL 1.1.1g (Affected 1.1.1d-1.1.1f).
Project Subscriptions
| Vendors | Products |
|---|---|
|
Broadcom
Subscribe
|
Fabric Operating System
Subscribe
|
|
Debian
Subscribe
|
Debian Linux
Subscribe
|
|
Fedoraproject
Subscribe
|
Fedora
Subscribe
|
|
Freebsd
Subscribe
|
Freebsd
Subscribe
|
|
Jdedwards
Subscribe
|
Enterpriseone
Subscribe
|
|
Netapp
Subscribe
|
|
|
Openssl
Subscribe
|
Openssl
Subscribe
|
|
Opensuse
Subscribe
|
Leap
Subscribe
|
|
Oracle
Subscribe
|
Application Server
Subscribe
Enterprise Manager Base Platform
Subscribe
Enterprise Manager For Storage Management
Subscribe
Enterprise Manager Ops Center
Subscribe
Http Server
Subscribe
Jd Edwards World Security
Subscribe
Mysql
Subscribe
Mysql Connectors
Subscribe
Mysql Enterprise Monitor
Subscribe
Mysql Workbench
Subscribe
Peoplesoft Enterprise Peopletools
Subscribe
|
|
Tenable
Subscribe
|
Log Correlation Engine
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-4661-1 | openssl security update |
Github GHSA |
GHSA-jq65-29v4-4x35 | Null pointer deference in openssl-src |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: openssl
Published:
Updated: 2024-09-17T03:13:46.200Z
Reserved: 2019-12-03T00:00:00
Link: CVE-2020-1967
No data.
Status : Modified
Published: 2020-04-21T14:15:11.287
Modified: 2024-11-21T05:11:45.023
Link: CVE-2020-1967
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
Github GHSA