cve/2023/CVE-2023-0464.md
2024-05-25 21:48:12 +02:00

1.5 KiB

CVE-2023-0464

Description

A security vulnerability has been identified in all supported versionsof OpenSSL related to the verification of X.509 certificate chainsthat include policy constraints. Attackers may be able to exploit thisvulnerability by creating a malicious certificate chain that triggersexponential use of computational resources, leading to a denial-of-service(DoS) attack on affected systems.Policy processing is disabled by default but can be enabled by passingthe -policy' argument to the command line utilities or by calling theX509_VERIFY_PARAM_set1_policies()' function.

POC

Reference

No PoCs from references.

Github