Summary
The X.400 address processing in X.509 GeneralName is exposed to a type confusion vulnerability. X.400 addresses when parsed as an ASN1_STRING while retaining the public structure definition for GENERAL_NAME as ASN1_TYPE, may allow OpenSSL function GENERAL_NAME_cmp to accept arbitrary pointers and perform memory reads.
Products Potentially Affected
OS/Product |
Exposure |
XIQ-SE |
No |
Network OS |
Investigating |
Repair Recommendations
None.
Please see the full security advisory article here for more details and updates.