SA-2023-025 - OpenSSL NULL dereference during PKCS7 data verification (CVE-2023-0401)
SummaryA NULL pointer can be dereferenced when signatures are being verified on PKCS7 signed or signedAndEnveloped data. In case the hash algorithm used for the signature is known to the OpenSSL libra...
![](https://community.extremenetworks.com/html/@92C2FC0A1351376EE5658FE00FA31438/assets/img_tile-default.png)