CVE-2022-3786


X.509 Email Address Variable Length Buffer Overflow

A buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification and requires either a CA to have signed a malicious certificate or for an application to continue certificate verification despite failure to construct a path to a trusted issuer. An attacker can craft a malicious email address in a certificate to overflow an arbitrary number of bytes containing the `.' character (decimal 46) on the stack. This buffer overflow could result in a crash (causing a denial of service). In a TLS client, this can be triggered by connecting to a malicious server. In a TLS server, this can be triggered if the server requests client authentication and a malicious client connects.



We have discovered 3,635 live websites that are affected by CVE-2022-3786.

Contact us to get more info




Affected Software

Product  OpenSSL
Category Web Server Extensions
Vulnerable Versions
  • from 3 before 3.0.7
Total Vulnerable Versions30
Vulnerable Domains3,635 live websites (0.33% of OpenSSL install base)



Details

  • Published - Nov 1, 2022
  • Updated - Nov 4, 2022

Credits

  • Viktor Dukhovni (finder)




Countries

United States1,020 websites



Germany530 websites
Finland339 websites
Italy194 websites
Japan146 websites
Netherlands94 websites
Singapore89 websites
Russia85 websites
France78 websites
Denmark78 websites

TLDs

.com1,121 websites
.org291 websites
.fi257 websites
.net246 websites
.de235 websites
.it148 websites
.io81 websites
.dk75 websites
.ru68 websites
.edu64 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


References


Websites affected by CVE-2022-3786

Top websites that are affected by CVE-2022-3786. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.eu Germany**,***
***.***.eu Germany**,***
***.*****.es Spain**,***
*****.******************.com United States**,***
****.****.org United States**,***
***.tm Turkmenistan**,***
********.com United States**,***
********.org United States***,***
****.****.org Germany***,***
*****************.com United States***,***
See full domain list