CVE-2020-1967

HIGH

OpenSSL 1.1.1d-1.1.1f - Denial of Service via Invalid Signature Algorithm in TLS 1.3 Handshake

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-1967. PoCs published by irsl.

AI-analyzed exploit summary This PoC demonstrates a DoS vulnerability in OpenSSL (CVE-2020-1967) by sending a crafted signature_algorithms_cert TLS extension during a TLS 1.3 handshake, causing a segmentation fault in vulnerable versions. The exploit requires a patched OpenSSL client and a server configured to call SSL_check_chain().

Description

Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signature_algorithms_cert" TLS extension. The crash occurs if an invalid or unrecognised signature algorithm is received from the peer. This could be exploited by a malicious peer in a Denial of Service attack. OpenSSL version 1.1.1d, 1.1.1e, and 1.1.1f are affected by this issue. This issue did not affect OpenSSL versions prior to 1.1.1d. Fixed in OpenSSL 1.1.1g (Affected 1.1.1d-1.1.1f).

Exploits (1)

nomisec WORKING POC 20 stars
by irsl · poc
https://github.com/irsl/CVE-2020-1967

This PoC demonstrates a DoS vulnerability in OpenSSL (CVE-2020-1967) by sending a crafted signature_algorithms_cert TLS extension during a TLS 1.3 handshake, causing a segmentation fault in vulnerable versions. The exploit requires a patched OpenSSL client and a server configured to call SSL_check_chain().

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target: OpenSSL 1.1.1d, 1.1.1e, 1.1.1f
No auth needed
Prerequisites: Vulnerable OpenSSL version (1.1.1d, 1.1.1e, or 1.1.1f) · Server or client application calling SSL_check_chain() · TLS 1.3 handshake
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (32)

Core 32
Core References
Patch, Third Party Advisory vendor-advisory x_refsource_freebsd
https://security.FreeBSD.org/advisories/FreeBSD-SA-20:11.openssl.asc
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2020/dsa-4661
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2020/04/22/2
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/202004-10
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2020/May/5
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00004.html
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00011.html
Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpujul2020.html
Third Party Advisory x_refsource_confirm
https://www.tenable.com/security/tns-2020-03
Vendor Advisory x_refsource_confirm
https://www.openssl.org/news/secadv/20200421.txt
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20200424-0003/
Exploit, Third Party Advisory x_refsource_misc
https://github.com/irsl/CVE-2020-1967
Third Party Advisory x_refsource_confirm
https://www.synology.com/security/advisory/Synology_SA_20_05
Third Party Advisory x_refsource_confirm
https://www.tenable.com/security/tns-2020-04
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuoct2020.html
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20200717-0004/
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpujan2021.html
Third Party Advisory x_refsource_confirm
https://www.tenable.com/security/tns-2020-11
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuApr2021.html
Third Party Advisory x_refsource_confirm
https://www.tenable.com/security/tns-2021-10
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com//security-alerts/cpujul2021.html
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuoct2021.html

Scores

CVSS v3 7.5
EPSS 0.6077
EPSS Percentile 98.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-476
Status published
Products (36)
broadcom/fabric_operating_system
crates.io/openssl-src 111.6.0 - 111.9.0crates.io
debian/debian_linux 9.0
debian/debian_linux 10.0
fedoraproject/fedora 30
fedoraproject/fedora 31
fedoraproject/fedora 32
freebsd/freebsd 12.1
jdedwards/enterpriseone < 9.2.5.0
netapp/active_iq_unified_manager 7.3
... and 26 more
Published Apr 21, 2020
Tracked Since Feb 18, 2026