Advisories for package 'openssl-src' › RustSec Advisory Database (original) (raw)

RUSTSEC-2023-0013: Vulnerability in openssl-src

NULL dereference during PKCS7 data verification

RUSTSEC-2023-0006: Vulnerability in openssl-src

X.400 address type confusion in X.509 GeneralName

RUSTSEC-2023-0009: Vulnerability in openssl-src

Use-after-free following BIO_new_NDEF

RUSTSEC-2023-0007: Vulnerability in openssl-src

Timing Oracle in RSA Decryption

RUSTSEC-2023-0011: Vulnerability in openssl-src

Invalid pointer dereference in d2i_PKCS7 functions

RUSTSEC-2023-0010: Vulnerability in openssl-src

Double free after calling PEM_read_bio_ex

RUSTSEC-2023-0012: Vulnerability in openssl-src

NULL dereference validating DSA public key

RUSTSEC-2023-0008: Vulnerability in openssl-src

X.509 Name Constraints Read Buffer Overflow

RUSTSEC-2022-0064: Vulnerability in openssl-src

X.509 Email Address 4-byte Buffer Overflow

RUSTSEC-2022-0065: Vulnerability in openssl-src

X.509 Email Address Variable Length Buffer Overflow

RUSTSEC-2022-0059: Vulnerability in openssl-src

Using a Custom Cipher with NID_undef may lead to NULL encryption

RUSTSEC-2022-0033: Vulnerability in openssl-src

Heap memory corruption with RSA private key operation

RUSTSEC-2022-0032: Vulnerability in openssl-src

AES OCB fails to encrypt some bytes

HIGH RUSTSEC-2022-0025: Vulnerability in openssl-src

Resource leakage when decoding certificates and keys

MEDIUM RUSTSEC-2022-0027: Vulnerability in openssl-src

OCSP_basic_verify may incorrectly verify the response signing certificate

MEDIUM RUSTSEC-2022-0026: Vulnerability in openssl-src

Incorrect MAC key used in the RC4-MD5 ciphersuite

RUSTSEC-2022-0014: Vulnerability in openssl-src

Infinite loop in BN_mod_sqrt() reachable when parsing certificates

RUSTSEC-2021-0129: Vulnerability in openssl-src

Invalid handling of X509_verify_cert() internal errors in libssl

HIGH RUSTSEC-2021-0098: Vulnerability in openssl-src

Read buffer overruns processing ASN.1 strings

CRITICAL RUSTSEC-2021-0097: Vulnerability in openssl-src

SM2 Decryption Buffer Overflow

HIGH RUSTSEC-2021-0057: Vulnerability in openssl-src

Integer overflow in CipherUpdate

HIGH RUSTSEC-2021-0056: Vulnerability in openssl-src

CA certificate check bypass with X509_V_FLAG_X509_STRICT

MEDIUM RUSTSEC-2021-0058: Vulnerability in openssl-src

Null pointer deref in X509_issuer_and_serial_hash()

MEDIUM RUSTSEC-2021-0055: Vulnerability in openssl-src

NULL pointer deref in signature_algorithms processing

HIGH RUSTSEC-2020-0015: Vulnerability in openssl-src

Crash causing Denial of Service attack