{"id":"GHSA-9qwg-crg9-m2vc","summary":"`openssl` `SubjectAlternativeName` and `ExtendedKeyUsage::other` allow arbitrary file read","details":"`SubjectAlternativeName` and `ExtendedKeyUsage` arguments were parsed using the OpenSSL function `X509V3_EXT_nconf`. This function parses all input using an OpenSSL mini-language which can perform arbitrary file reads.\n\nThanks to David Benjamin (Google) for reporting this issue.\n","aliases":["RUSTSEC-2023-0023"],"modified":"2023-11-08T04:18:04.563523Z","published":"2023-03-24T22:01:29Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2023-03-24T22:01:29Z","nvd_published_at":null,"cwe_ids":[]},"references":[{"type":"WEB","url":"https://github.com/sfackler/rust-openssl/pull/1854"},{"type":"PACKAGE","url":"https://github.com/sfackler/rust-openssl"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2023-0023.html"}],"affected":[{"package":{"name":"openssl","ecosystem":"crates.io","purl":"pkg:cargo/openssl"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.9.7"},{"fixed":"0.10.48"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/03/GHSA-9qwg-crg9-m2vc/GHSA-9qwg-crg9-m2vc.json"}}],"schema_version":"1.9.0"}