{"id":"GHSA-6hcf-g6gr-hhcr","aliases":["RUSTSEC-2023-0024"],"url":"https://o3.security/vulnerability/GHSA-6hcf-g6gr-hhcr","summary":"`openssl` `X509Extension::new` and `X509Extension::new_nid` null pointer dereference","details":"These functions would crash when the context argument was None with certain extension types.\n\nThanks to David Benjamin (Google) for reporting this issue.\n","published":"2023-03-24T22:01:23Z","modified":"2023-11-08T04:16:17.438606Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"openssl","fixedVersion":"0.10.48"}],"fix":{"url":"https://github.com/sfackler/rust-openssl/pull/1854","label":"sfackler/rust-openssl#1854"},"references":[{"type":"WEB","url":"https://github.com/sfackler/rust-openssl/pull/1854"},{"type":"PACKAGE","url":"https://github.com/sfackler/rust-openssl"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2023-0024.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-11-08T04:16:17.438606Z"}}