Server denial-of-service by using sslv2 message format in a HelloRetryRequest handshake
LowPublished Sep 27, 2022
If a TLS1.3 enabled s2n-tls server receives an sslv2 ClientHello format message in a HelloRetryRequest handshake, the server may restart due to a NULL pointer dereference. Applications using s2n are expected to restart following a NULL pointer dereference, and client applications may also retry requests. No AWS service was impacted by this issue and AWS customers do not need to take any action. s2n-tls users who enabled TLS1.3 in their applications should update to the most recent s2n-tls version. All versions of s2n-tls from commit 397382111523a94f95cc551c4ca4d1eaf884ef35 through commit c947a221e1caadf12a262a6bf548f5f082e096be are affected by this issue. Affected s2n-tls users should fetch s2n-tls commit 8cf81d3976dddb00b0050b0cfafcb41ea2a3bde5.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| s2n-tls Product | < <v1.3.23 | <v1.3.23 |
Details and references
- Severity from
- GitHub (reviewed advisory)
More AWS advisories
All AWS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Feb 142023 | Issue with parsing Certificate Common Name (CN) in s2n-tls | Low | v1.3.35 |
| Dec 102022 | Privilege Escalation Vector in CloudWatch Agent for Windows | High7.1 | 1.247355 |
| Sep 272022 | Issue with configuring session ticket names in s2n-tls | Medium | v1.3.23 |
| Aug 92022 | Partial Path Traversal in aws-cpp-sdk-transfer | Medium | v1.9.318 |
| Jul 152022 | Partial Path Traversal in com.amazonaws:aws-java-sdk-s3 | High7.9 | 1.12.261 |
| May 162022 | Security vulnerability in a third party software, Slurm < 20.11.9 and 21.08.8 | Critical | 20.11.9 |