OpenSSL是OpenSSL团队的一个开源的能够实现安全套接层(SSLv2/v3)和安全传输层(TLSv1)协议的通用加密库。该产品支持多种加密算法,包括对称密码、哈希算法、安全散列算法等。 OpenSSL 3.6版本、3.5版本、3.4版本、3.3版本、3.0版本和1.1.1版本存在安全漏洞,该漏洞源于PKCS#12解析代码存在类型混淆,未验证类型即访问ASN1_TYPE联合体成员,可能导致处理畸形PKCS#12文件时取消引用无效或空指针,引发拒绝服务。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-22796 | ASN1_TYPE Type Confusion in the PKCS7_digest_from_attributes() function | |
| CVE-2025-15467 | Stack buffer overflow in CMS (Auth)EnvelopedData parsing | |
| CVE-2025-15469 | 'openssl dgst' one-shot codepath silently truncates inputs >16MB | |
| CVE-2025-15468 | NULL dereference in SSL_CIPHER_find() function on unknown cipher ID | |
| CVE-2025-66199 | TLS 1.3 CompressedCertificate excessive memory allocation | |
| CVE-2025-68160 | Heap out-of-bounds write in BIO_f_linebuffer on short writes | |
| CVE-2025-11187 | Improper validation of PBMAC1 parameters in PKCS#12 MAC verification | |
| CVE-2025-69421 | NULL Pointer Dereference in PKCS12_item_decrypt_d2i_ex function | |
| CVE-2025-69420 | Missing ASN1_TYPE validation in TS_RESP_verify_response() function | |
| CVE-2025-69419 | Out of bounds write in PKCS12_get_friendlyname() UTF-8 conversion | |
| CVE-2025-69418 | Unauthenticated/unencrypted trailing bytes with low-level OCB function calls |
No comments yet