Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-69420

Опубликовано: 27 янв. 2026
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS3: 7.5

Описание

Issue summary: A type confusion vulnerability exists in the TimeStamp Response verification code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing a malformed TimeStamp Response file. Impact summary: An application calling TS_RESP_verify_response() with a malformed TimeStamp Response can be caused to dereference an invalid or NULL pointer when reading, resulting in a Denial of Service. The functions ossl_ess_get_signing_cert() and ossl_ess_get_signing_cert_v2() access the signing cert attribute value without validating its type. When the type is not V_ASN1_SEQUENCE, this results in accessing invalid memory through the ASN1_TYPE union, causing a crash. Exploiting this vulnerability requires an attacker to provide a malformed TimeStamp Response to an application that verifies timestamp responses. The TimeStamp protocol (RFC 3161) is not widely used and the impact of the exploit is just a Denial...

РелизСтатусПримечание
devel

not-affected

code not compiled
esm-apps-legacy/xenial

not-affected

code not compiled
esm-apps/bionic

not-affected

code not compiled
esm-apps/xenial

not-affected

code not compiled
esm-infra/focal

not-affected

code not compiled
jammy

not-affected

code not compiled
noble

not-affected

code not compiled
plucky

ignored

end of life, was needs-triage
questing

not-affected

code not compiled
resolute

not-affected

code not compiled

Показывать по

РелизСтатусПримечание
devel

not-affected

uses system openssl
esm-apps-legacy/xenial

needs-triage

esm-apps/bionic

needs-triage

esm-apps/focal

not-affected

uses system openssl
esm-apps/jammy

needed

esm-apps/noble

not-affected

uses system openssl
esm-apps/resolute

not-affected

uses system openssl
esm-apps/xenial

ignored

end of ESM support, was needs-triage
esm-infra-legacy/trusty

not-affected

uses system openssl
jammy

needed

Показывать по

РелизСтатусПримечание
devel

released

3.5.5-1ubuntu1
esm-infra-legacy/trusty

not-affected

1.1.1+ only
esm-infra-legacy/xenial

not-affected

1.1.1+ only
esm-infra/bionic

released

1.1.1-1ubuntu2.1~18.04.23+esm7
esm-infra/focal

released

1.1.1f-1ubuntu2.24+esm2
esm-infra/xenial

not-affected

1.1.1+ only
fips-preview/jammy

needed

fips-updates/bionic

released

1.1.1-1ubuntu2.fips.2.1~18.04.23.7
fips-updates/focal

released

1.1.1f-1ubuntu2.fips.24.2
fips-updates/jammy

released

3.0.2-0ubuntu1.21+Fips1

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra/bionic

not-affected

1.1.1+ only
jammy

DNE

noble

DNE

plucky

DNE

questing

DNE

resolute

DNE

upstream

needs-triage

Показывать по

EPSS

Процентиль: 52%
0.00768
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 5.9
redhat
6 месяцев назад

Issue summary: A type confusion vulnerability exists in the TimeStamp Response verification code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing a malformed TimeStamp Response file. Impact summary: An application calling TS_RESP_verify_response() with a malformed TimeStamp Response can be caused to dereference an invalid or NULL pointer when reading, resulting in a Denial of Service. The functions ossl_ess_get_signing_cert() and ossl_ess_get_signing_cert_v2() access the signing cert attribute value without validating its type. When the type is not V_ASN1_SEQUENCE, this results in accessing invalid memory through the ASN1_TYPE union, causing a crash. Exploiting this vulnerability requires an attacker to provide a malformed TimeStamp Response to an application that verifies timestamp responses. The TimeStamp protocol (RFC 3161) is not widely used and the impact of the exploit is just a Denial...

CVSS3: 7.5
nvd
6 месяцев назад

Issue summary: A type confusion vulnerability exists in the TimeStamp Response verification code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing a malformed TimeStamp Response file. Impact summary: An application calling TS_RESP_verify_response() with a malformed TimeStamp Response can be caused to dereference an invalid or NULL pointer when reading, resulting in a Denial of Service. The functions ossl_ess_get_signing_cert() and ossl_ess_get_signing_cert_v2() access the signing cert attribute value without validating its type. When the type is not V_ASN1_SEQUENCE, this results in accessing invalid memory through the ASN1_TYPE union, causing a crash. Exploiting this vulnerability requires an attacker to provide a malformed TimeStamp Response to an application that verifies timestamp responses. The TimeStamp protocol (RFC 3161) is not widely used and the impact of the exploit is just a Denial

CVSS3: 7.5
debian
6 месяцев назад

Issue summary: A type confusion vulnerability exists in the TimeStamp ...

CVSS3: 7.5
github
6 месяцев назад

Issue summary: A type confusion vulnerability exists in the TimeStamp Response verification code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing a malformed TimeStamp Response file. Impact summary: An application calling TS_RESP_verify_response() with a malformed TimeStamp Response can be caused to dereference an invalid or NULL pointer when reading, resulting in a Denial of Service. The functions ossl_ess_get_signing_cert() and ossl_ess_get_signing_cert_v2() access the signing cert attribute value without validating its type. When the type is not V_ASN1_SEQUENCE, this results in accessing invalid memory through the ASN1_TYPE union, causing a crash. Exploiting this vulnerability requires an attacker to provide a malformed TimeStamp Response to an application that verifies timestamp responses. The TimeStamp protocol (RFC 3161) is not widely used and the impact of the exploit is just a Den...

CVSS3: 7.5
redos
3 месяца назад

Уязвимость openssl3

EPSS

Процентиль: 52%
0.00768
Низкий

7.5 High

CVSS3