FlawAtlas
Search the atlas
UBUNTU-CVE-2023-0286 High

UBUNTU-CVE-2023-0286

There is a type confusion vulnerability relating to X.400 address processing inside an X.509 GeneralName. X.400 addresses were parsed as an ASN1_STRING but the public structure definition for GENERAL_NAME incorrectly specified the type of the x400Address field as ASN1_TYPE. This field is subsequently interpreted by the OpenSSL function GENERAL_NAME_cmp as an ASN1_TYPE rather than an ASN1_STRING. When CRL checking is enabled (i.e. the application sets the X509_V_FLAG_CRL_CHECK flag), this vulnerability may allow an attacker to pass arbitrary pointers to a memcmp call, enabling them to read memory contents or enact a denial of service. In most cases, the attack requires the attacker to provide both the certificate chain and CRL, neither of which need to have a valid signature. If the attacker only controls one of these inputs, the other input must already contain an X.400 address as a CRL distribution point, which is uncommon. As such, this vulnerability is most likely to only affect applications which have implemented their own functionality for retrieving CRLs over a network.

Exploit probability Not scored
Published February 7, 2023
Required by Not available
Last source change April 22, 2026

02 / AFFECTED SOFTWARE

Affected packages

Ubuntu:18.04:LTS openssl

25 explicit affected versions

Ubuntu:18.04:LTS openssl1.0

14 explicit affected versions

Ubuntu:20.04:LTS edk2

15 explicit affected versions

Ubuntu:20.04:LTS openssl

18 explicit affected versions

Ubuntu:22.04:LTS edk2

13 explicit affected versions

Ubuntu:22.04:LTS nodejs

7 explicit affected versions

Ubuntu:22.04:LTS openssl

10 explicit affected versions

Ubuntu:Pro:14.04:LTS openssl

34 explicit affected versions

Ubuntu:Pro:16.04:LTS edk2

7 explicit affected versions

Ubuntu:Pro:16.04:LTS openssl

30 explicit affected versions

Ubuntu:Pro:18.04:LTS edk2

12 explicit affected versions

Ubuntu:Pro:FIPS-updates:18.04:LTS openssl

12 explicit affected versions

Ubuntu:Pro:FIPS-updates:20.04:LTS openssl

6 explicit affected versions

Ubuntu:Pro:FIPS:16.04:LTS openssl

10 explicit affected versions

Ubuntu:Pro:FIPS:16.04:LTS openssl

7 explicit affected versions

Ubuntu:Pro:FIPS:18.04:LTS openssl

2 explicit affected versions

Ubuntu:Pro:FIPS:20.04:LTS openssl

2 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities UBUNTU-CVE-2023-0286

There is a type confusion vulnerability relating to X.400 address processing inside an X.509 GeneralName. X.400 addresses were parsed as an ASN1_STRING but the public structure definition for GENERAL_NAME incorrectly specified the type of the x400Address field as ASN1_TYPE. This field is subsequently interpreted by the OpenSSL function GENERAL_NAME_cmp as an ASN1_TYPE rather than an ASN1_STRING. When CRL checking is enabled (i.e. the application sets the X509_V_FLAG_CRL_CHECK flag), this vulnerability may allow an attacker to pass arbitrary pointers to a memcmp call, enabling them to read memory contents or enact a denial of service. In most cases, the attack requires the attacker to provide both the certificate chain and CRL, neither of which need to have a valid signature. If the attacker only controls one of these inputs, the other input must already contain an X.400 address as a CRL distribution point, which is uncommon. As such, this vulnerability is most likely to only affect applications which have implemented their own functionality for retrieving CRLs over a network.

View original source

05 / REFERENCES

Further evidence