37532b3
diff -rupN --no-dereference openssl-3.0.9/crypto/asn1/a_verify.c openssl-3.0.9-new/crypto/asn1/a_verify.c
37532b3
--- openssl-3.0.9/crypto/asn1/a_verify.c	2023-05-30 14:31:57.000000000 +0200
addc253
+++ openssl-3.0.9-new/crypto/asn1/a_verify.c	2023-05-31 16:36:51.578279278 +0200
bae47f5
@@ -153,6 +153,11 @@ int ASN1_item_verify_ctx(const ASN1_ITEM
eb35cbc
             ERR_raise(ERR_LIB_ASN1, ERR_R_EVP_LIB);
eb35cbc
         if (ret <= 1)
eb35cbc
             goto err;
eb35cbc
+    } else if ((mdnid == NID_md5
eb35cbc
+               && ossl_safe_getenv("OPENSSL_ENABLE_MD5_VERIFY") == NULL) ||
eb35cbc
+               mdnid == NID_md4 || mdnid == NID_md2 || mdnid == NID_sha) {
eb35cbc
+        ERR_raise(ERR_LIB_ASN1, ASN1_R_UNKNOWN_MESSAGE_DIGEST_ALGORITHM);
eb35cbc
+        goto err;
eb35cbc
     } else {
eb35cbc
         const EVP_MD *type = NULL;
eb35cbc