CVE-2022-0778
CVE-2022-0778 copied to clipboard
Unable to send crafted dangerous certificate in a request
Hi All,
I was trying to send dangerous certificate to the server (in my internal setup) using openssl s_client and curl, but not able to send due to not vulnerbale openssl was not able to parse it properly and vulnerable openssl was hung itself. Attached screenshots of the same.
Do anyone have idea how we can send request with dangerous certificate ?
Error while using not vulnerable openssl s_client:
Error while trying with curl:
Maybe your should change the source code, or use debugger to substitute the cert content just before sending the CERTIFICATE message.
Yes, I guess it would need something like that. I still see this after regenerating a vulnerable cert to match the key, solving https://github.com/drago-96/CVE-2022-0778/issues/8
Thanks @catbro666 and @martindorey for your response !! Yeah I will try the same.