FreeBSD-SA-20:11.openssl

Status
Not open for further replies.

admin

Administrator
Staff member
Administrator
Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signature_algorithms_cert" TLS extension. The crash occurs if an invalid or unrecognized signature algorithm is received from the peer.
Continue reading...
 
Status
Not open for further replies.
Back
Top