{"id":"GHSA-9qwg-crg9-m2vc","aliases":["RUSTSEC-2023-0023"],"url":"https://o3.security/vulnerability/GHSA-9qwg-crg9-m2vc","summary":"`openssl` `SubjectAlternativeName` and `ExtendedKeyUsage::other` allow arbitrary file read","details":"`SubjectAlternativeName` and `ExtendedKeyUsage` arguments were parsed using the OpenSSL function `X509V3_EXT_nconf`. This function parses all input using an OpenSSL mini-language which can perform arbitrary file reads.\n\nThanks to David Benjamin (Google) for reporting this issue.\n","published":"2023-03-24T22:01:29Z","modified":"2023-11-08T04:18:04.563523Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"openssl","fixedVersion":"0.10.48"}],"fix":{"url":"https://github.com/sfackler/rust-openssl/pull/1854","label":"sfackler/rust-openssl#1854"},"references":[{"type":"WEB","url":"https://github.com/sfackler/rust-openssl/pull/1854"},{"type":"PACKAGE","url":"https://github.com/sfackler/rust-openssl"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2023-0023.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-11-08T04:18:04.563523Z"}}