CVE-2023-0465: Invalid certificate policies in leaf certificates are silently ignored

Published Mar 28, 2023
·
Updated

Applications that use a non-default option when verifying certificates may be vulnerable to an attack from a malicious CA to circumvent certain checks.

Invalid certificate policies in leaf certificates are silently ignored by OpenSSL and other certificate policy checks are skipped for that certificate. A malicious CA could use this to deliberately assert invalid certificate policies in order to circumvent policy checking on the certificate altogether.

Policy processing is disabled by default but can be enabled by passing the -policy' argument to the command line utilities or by calling the X509VERIFYPARAMset1policies()' function.

Affected Software

12 affected componentsFixes available
debian/openssl<=1.1.1n-0+deb10u3
1.1.1n-0+deb10u61.1.1w-0+deb11u11.1.1n-0+deb11u53.0.11-1~deb12u23.1.4-2
OpenSSL OpenSSL>=1.0.2<1.0.2zh
OpenSSL OpenSSL>=1.1.1<1.1.1u
OpenSSL OpenSSL>=3.0.0<3.0.9
OpenSSL OpenSSL>=3.1.0<3.1.1
Microsoft cbl2 edk2 20230301gitf80f052277c8-37
Microsoft cbl2 kata-containers-cc 0.4.1-2
Microsoft cm1 openssl 1.1.1k-15
Microsoft azl3 edk2 20230301gitf80f052277c8-37
Microsoft cbl2 hvloader 1.0.1-11
Microsoft cbl2 openssl 1.1.1k-23
Microsoft cbl2 hvloader 1.0.1-9

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade debian/openssl to a version that resolves this vulnerability.

    Fixed in 1.1.1n-0+deb10u6Fixed in 1.1.1w-0+deb11u1Fixed in 1.1.1n-0+deb11u5Fixed in 3.0.11-1~deb12u2Fixed in 3.1.4-2

Event History

Mar 28, 2023
CVE Published
via MITRE·02:30 PM
Data Sourced
via MITRE·02:30 PM
DescriptionWeakness
Data Sourced
via NVD·03:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Mar 29, 2023
Data Sourced
via Red Hat·03:17 AM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What is CVE-2023-0465?

CVE-2023-0465 is a vulnerability that affects applications using a non-default option when verifying certificates, making them vulnerable to attacks from malicious certificate authorities.

2

How does CVE-2023-0465 impact OpenSSL?

CVE-2023-0465 affects OpenSSL by allowing invalid certificate policies in leaf certificates to be silently ignored and certain certificate policy checks to be skipped.

3

Which versions of OpenSSL are affected by CVE-2023-0465?

OpenSSL versions 1.1.1n-0+deb10u3 to 1.1.1n-0+deb10u6, 1.1.1n-0+deb11u4 to 1.1.1n-0+deb11u5, 3.0.9-1 to 3.0.11-1 are affected by CVE-2023-0465.

4

How can I fix CVE-2023-0465 in OpenSSL?

To fix CVE-2023-0465 in OpenSSL, update to version 1.1.1n-0+deb10u6 or higher for Debian 10, and version 1.1.1n-0+deb11u5 or higher for Debian 11.

5

Where can I find more information about CVE-2023-0465?

You can find more information about CVE-2023-0465 on the OpenSSL security advisory at https://www.openssl.org/news/secadv/20230328.txt and the associated commits in the OpenSSL Git repository.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203