CVE-2022-4203

X.509 Name Constraints Read Buffer Overflow

A read buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification and requires either a CA to have signed the malicious certificate or for the application to continue certificate verification despite failure to construct a path to a trusted issuer. The read buffer overrun might result in a crash which could lead to a denial of service attack. In theory it could also result in the disclosure of private memory contents (such as private keys, or sensitive plaintext) although we are not aware of any working exploit leading to memory contents disclosure as of the time of release of this advisory. In a TLS client, this can be triggered by connecting to a malicious server. In a TLS server, this can be triggered if the server requests client authentication and a malicious client connects.


We have discovered 16,092 live websites that are affected by CVE-2022-4203.

Test my site




Affected Software

Product  OpenSSL
Category Web Server Extensions
Vulnerable Domains16,092 live websites (2.40% of OpenSSL install base)
Vulnerable Versions
  • from 3 before 3.0.8
Vulnerable Versions Count7 versions ( 17.50% of all versions)



Details

  • Published - Feb 24, 2023
  • Updated - Feb 13, 2025

Credits

  • Corey Bonnell from Digicert (finder)
  • Viktor Dukhovni (remediation developer)

CVE-2022-4203 usage by Country

United States3,623 websites



France2,345 websites
Germany1,486 websites
Japan1,317 websites
Canada848 websites
GB774 websites
Finland688 websites
Netherlands523 websites
Italy404 websites
Hungary397 websites

CVE-2022-4203 usage by TLD

.com5,684 websites
.org685 websites
.edu652 websites
.net643 websites
.ca638 websites
.fi534 websites
.jp534 websites
.fr489 websites
.de439 websites
.co.uk422 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2022-4203

Top websites that are affected by CVE-2022-4203. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.com United States*,***
***.edu United States**,***
******.org Singapore**,***
********.org France**,***
********.com United States**,***
*******.net Japan**,***
******.****.edu United States**,***
************************.com United States**,***
***.com United States**,***
******.com United States**,***
See full domain list

FAQ

A total of 16,092 websites have been identified as vulnerable to CVE-2022-4203, discovered through global website indexing conducted by WebTechSurvey.
OpenSSL is susceptible to CVE-2022-4203 vulnerability.
OpenSSL versions before 3.0.8 are vulnerable to CVE-2022-4203.
Version 3.0.8 of OpenSSL addresses the CVE-2022-4203 security vulnerability.