CVE-2022-4203 is a read buffer overrun vulnerability in OpenSSL's X.509 certificate verification, specifically during name constraint checking. This flaw can be triggered by malicious certificates, potentially leading to a denial of service. While memory content disclosure is theoretically possible, no working exploits for this impact are known. Rated Medium (CVSS 4.9), it requires either a compromised CA or an application that continues verification despite path failures. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion beyond a few mentions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.0.0, < 3.0.8CPE matchmatch criteria | cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.