BSA-2020-948
Summary Security Advisory ID : BSA-2020-948 Component : OpenSSL Revision : 1.0
Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signature_algorithms_cert" TLS extension. The crash occurs if an invalid or unrecognized signature algorithm is received from the peer. This could be exploited by a malicious peer in a Denial of Service attack. OpenSSL version 1.1.1d, 1.1.1e, and 1.1.1f are affected by this issue. This issue did not affect OpenSSL versions prior to 1.1.1d. Fixed in OpenSSL 1.1.1g (Affected 1.1.1d-1.1.1f).
Affected Products
Brocade Fabric OS versions before v9.0.1a, and after Brocade Fabric OS version v9.0.
Note: Brocade Fabric OS v8.2.x, v8.1.x and v7.4.x are not impacted.
Workaround.
- Use seccryptocfg command to change the ciphers.
Products Confirmed Not Vulnerable
No other Brocade Fibre Channel Products from Broadcom products are currently known to be affected by this vulnerability.
Solution
A security update has been provided in Brocade Fabric OS versions v9.0.1a.
Credit
This issue was discovered through security testing.
Revision History
| Version | Change | Date |
|---|---|---|
| 1.0 | Initial Publication | May 10, 2021 |