From nobody Tue Sep 03 15:53:26 2024 X-Original-To: freebsd-security@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4Wyqsk0Z1sz5TSrY for ; Tue, 03 Sep 2024 15:53:30 +0000 (UTC) (envelope-from cy.schubert@cschubert.com) Received: from omta001.cacentral1.a.cloudfilter.net (omta001.cacentral1.a.cloudfilter.net [3.97.99.32]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client CN "Client", Issuer "CA" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4Wyqsj3BR1z56fP for ; Tue, 3 Sep 2024 15:53:29 +0000 (UTC) (envelope-from cy.schubert@cschubert.com) Authentication-Results: mx1.freebsd.org; dkim=none; dmarc=pass (policy=quarantine) header.from=cschubert.com; spf=pass (mx1.freebsd.org: domain of cy.schubert@cschubert.com designates 3.97.99.32 as permitted sender) smtp.mailfrom=cy.schubert@cschubert.com Received: from shw-obgw-4001a.ext.cloudfilter.net ([10.228.9.142]) by cmsmtp with ESMTPS id lTyJsQgUh9TOUlVqSsXgXS; Tue, 03 Sep 2024 15:53:28 +0000 Received: from spqr.komquats.com ([70.66.152.170]) by cmsmtp with ESMTPSA id lVqRsblqRGvSVlVqSsE54P; Tue, 03 Sep 2024 15:53:28 +0000 X-Auth-User: cschuber X-Authority-Analysis: v=2.4 cv=FpSm/Hrq c=1 sm=1 tr=0 ts=66d730f8 a=y8EK/9tc/U6QY+pUhnbtgQ==:117 a=y8EK/9tc/U6QY+pUhnbtgQ==:17 a=kj9zAlcOel0A:10 a=EaEq8P2WXUwA:10 a=YxBL1-UpAAAA:8 a=6I5d2MoRAAAA:8 a=EkcXrb_YAAAA:8 a=Ntg_Zx-WAAAA:8 a=s9e2T47jAAAA:8 a=NIO6eqGWrWBsO9KYZwEA:9 a=CjuIK1q_8ugA:10 a=Ia-lj3WSrqcvXOmTRaiG:22 a=LK5xJRSDVpKd5WXXoEvA:22 a=RUfouJl5KNV7104ufCm4:22 a=CxX688lCtmX4rDtm-yj2:22 Received: from slippy.cwsent.com (slippy [10.1.1.91]) by spqr.komquats.com (Postfix) with ESMTP id C6C8D157 for ; Tue, 03 Sep 2024 08:53:26 -0700 (PDT) Received: by slippy.cwsent.com (Postfix, from userid 1000) id C282E207; Tue, 03 Sep 2024 08:53:26 -0700 (PDT) X-Mailer: exmh version 2.9.0 11/07/2018 with nmh-1.8+dev Reply-to: Cy Schubert From: Cy Schubert X-os: FreeBSD X-Sender: cy@cwsent.com X-URL: http://www.cschubert.com/ To: freebsd-security@freebsd.org Subject: OpenSSL Security Advisory (fwd) List-Id: Security issues List-Archive: https://lists.freebsd.org/archives/freebsd-security List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: freebsd-security@freebsd.org Sender: owner-freebsd-security@FreeBSD.org Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Date: Tue, 03 Sep 2024 08:53:26 -0700 Message-Id: <20240903155326.C282E207@slippy.cwsent.com> X-CMAE-Envelope: MS4xfEtCRdEUOhRIqqnXzE9c9gYOU4/lsN2SmYSio1LsszBEYlC7JI74dabIHp2ys3RsjEwEIEdW5yMyPNlFPNxT+yS0BodhELoqJenKS5Pn3Z+yjpjXnO1a Hl+5pozKIdcXkzAO+YPGZq5fgmaVmWTwnz/5iNarMCMtxrbBAeRzueBWXeM84lwzh/Aek8ItTaChu9LvFr9YUkAfJW4SC0M+3iI= X-Spamd-Bar: --- X-Spamd-Result: default: False [-3.56 / 15.00]; NEURAL_HAM_LONG(-1.00)[-1.000]; NEURAL_HAM_MEDIUM(-1.00)[-1.000]; NEURAL_HAM_SHORT(-0.96)[-0.955]; MV_CASE(0.50)[]; DMARC_POLICY_ALLOW(-0.50)[cschubert.com,quarantine]; R_SPF_ALLOW(-0.20)[+ip4:3.97.99.32/31]; RWL_MAILSPIKE_VERYGOOD(-0.20)[3.97.99.32:from]; RCVD_IN_DNSWL_LOW(-0.10)[3.97.99.32:from]; MIME_GOOD(-0.10)[text/plain]; ARC_NA(0.00)[]; MIME_TRACE(0.00)[0:+]; RCPT_COUNT_ONE(0.00)[1]; RCVD_VIA_SMTP_AUTH(0.00)[]; ASN(0.00)[asn:16509, ipnet:3.96.0.0/15, country:US]; R_DKIM_NA(0.00)[]; MLMMJ_DEST(0.00)[freebsd-security@freebsd.org]; TO_DN_NONE(0.00)[]; FROM_EQ_ENVFROM(0.00)[]; FROM_HAS_DN(0.00)[]; HAS_REPLYTO(0.00)[Cy.Schubert@cschubert.com]; TO_MATCH_ENVRCPT_ALL(0.00)[]; RCVD_TLS_LAST(0.00)[]; PREVIOUSLY_DELIVERED(0.00)[freebsd-security@freebsd.org]; RCVD_COUNT_THREE(0.00)[4]; REPLYTO_EQ_FROM(0.00)[] X-Rspamd-Queue-Id: 4Wyqsj3BR1z56fP Is this something we need to concern ourselves with? -- Cheers, Cy Schubert FreeBSD UNIX: Web: https://FreeBSD.org NTP: Web: https://nwtime.org e^(i*pi)+1=0 ------- Forwarded Message Date: Tue, 03 Sep 2024 17:48:34 +0200 From: Tomas Mraz To: openssl-project , openssl-users , openssl-announce@openssl.org Subject: OpenSSL Security Advisory - --=-Tb6QWSUhNjkYHW+t2XR3 Content-Type: text/plain; charset="UTF-8" OpenSSL Security Advisory [3rd September 2024] ============================================== Possible denial of service in X.509 name checks (CVE-2024-6119) =============================================================== Severity: Moderate Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address resulting in abnormal termination of the application process. Impact summary: Abnormal termination of an application can a cause a denial of service. Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address when comparing the expected name with an `otherName` subject alternative name of an X.509 certificate. This may result in an exception that terminates the application program. Note that basic certificate chain validation (signatures, dates, ...) is not affected, the denial of service can occur only when the application also specifies an expected DNS name, Email address or IP address. TLS servers rarely solicit client certificates, and even when they do, they generally don't perform a name check against a "reference identifier" (expected identity), but rather extract the presented identity after checking the certificate chain. So TLS servers are generally not affected and the severity of the issue is Moderate. The FIPS modules in 3.3, 3.2, 3.1 and 3.0 are not affected by this issue. OpenSSL 1.1.1 and 1.0.2 are also not affected by this issue. OpenSSL 3.3, 3.2, 3.1 and 3.0 are vulnerable to this issue. OpenSSL 3.3 users should upgrade to OpenSSL 3.3.2 OpenSSL 3.2 users should upgrade to OpenSSL 3.2.3 OpenSSL 3.1 users should upgrade to OpenSSL 3.1.7 OpenSSL 3.0 users should upgrade to OpenSSL 3.0.15 This issue was reported on 16th June 2024 by David Benjamin (Google), reiterating an AddressSanitizer issue raised on 30th September 2021. The fix was developed by Viktor Dukhovni. General Advisory Notes ====================== URL for this Security Advisory: https://openssl-library.org/news/secadv/20240903.txt Note: the online version of the advisory may be updated with additional details over time. For details of OpenSSL severity classifications please see: https://openssl-library.org/policies/general/security-policy/ - -- You received this message because you are subscribed to the Google Groups "open ssl-announce" group. To unsubscribe from this group and stop receiving emails from it, send an email to openssl-announce+unsubscribe@openssl.org. - --=-Tb6QWSUhNjkYHW+t2XR3 Content-Type: application/pgp-signature; name="signature.asc" Content-Description: This is a digitally signed message part - -----BEGIN PGP SIGNATURE----- iQJGBAABCAAwFiEE3HAyZir4heL0fyQ/UnRmohynnm0FAmbXL9ISHHRvbWFzQG9w ZW5zc2wub3JnAAoJEFJ0ZqIcp55t3tMP/iX+ChDF+5bG9INwMmRW7JPW8HQD4MOS glVR1LlB7Rn2tzQ5brwUnoR5Q6kgYhfAx+7bCeqqdAyJO/NZIqgbzyHJINBupjZ/ POaBLLT3m6JlzX/8b7C1syM9+YWxx06g4PCsAJvjyWm04oCIGC8scepV/686Ot5y yUcko3Kxte6w9xXoSYRPS+e8FTyGVCcFReZyO/pgbAXU2WV1J1pHjqKjUSVQ7u6N Yl1XYaMvhB612G/aTl1RbUXDFYUFi/ExHkrCsTdV6/j7tSLp+EwR4awz5wy/WbC3 JREUVYcCw8oY6KX13YR+A6t0gLbL8tc1W08gI2x6yOa/ojSLlGkeETikgU4bCy0U VUcZCcWK9P3zqv7horuQXZIjMGl4dOR7el2KC+EsC3iMu1xoSVgwAyyhViq1CY8G DEHpOiuJW0KeXoZUASwHc0OyAFtGhR//ybdEBKbGwKQuYvxi8Mgd/tNhBphvKPWC ITB9R6kp9vcm2SK6saaXMrvt4UpisLM9k+2yteLIJxckqgBaCiUGW3ShMAn5BTM1 ps/LIouXT7WR9y8xROQ4W82ozlb/JK2Z+QTVKwrKMQ+5/IKmaqI06MrcPyu6OKgB 3zZs7vxVDl7Ul1+dM2OV1C2Bw9ir/dMOtpbxZY5HYaZG87Ch0m/R5sFKHgbxKnUl kA7jwz5HuD25 =sAhI - -----END PGP SIGNATURE----- - --=-Tb6QWSUhNjkYHW+t2XR3-- ------- End of Forwarded Message