Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-23840


Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output length argument in some cases where the input length is close to the maximum permissable length for an integer on the platform. In such cases the return value from the function call will be 1 (indicating success), but the output length value will be negative. This could cause applications to behave incorrectly or crash. OpenSSL versions 1.1.1i and below are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1j. OpenSSL versions 1.0.2x and below are affected by this issue. However OpenSSL 1.0.2 is out of support and no longer receiving public updates. Premium support customers of OpenSSL 1.0.2 should upgrade to 1.0.2y. Other users should upgrade to 1.1.1j. Fixed in OpenSSL 1.1.1j (Affected 1.1.1-1.1.1i). Fixed in OpenSSL 1.0.2y (Affected 1.0.2-1.0.2x).


Published

2021-02-16T17:15:13.300

Last Modified

2024-11-21T05:51:55.210

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-190

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application openssl openssl < 1.0.2y Yes
Application openssl openssl < 1.1.1j Yes
Operating System debian debian_linux 10.0 Yes
Application tenable log_correlation_engine < 6.0.8 Yes
Application tenable nessus_network_monitor 5.11.0 Yes
Application tenable nessus_network_monitor 5.11.1 Yes
Application tenable nessus_network_monitor 5.12.0 Yes
Application tenable nessus_network_monitor 5.12.1 Yes
Application tenable nessus_network_monitor 5.13.0 Yes
Application oracle business_intelligence 5.5.0.0.0 Yes
Application oracle business_intelligence 5.9.0.0.0 Yes
Application oracle business_intelligence 12.2.1.3.0 Yes
Application oracle business_intelligence 12.2.1.4.0 Yes
Application oracle communications_cloud_native_core_policy 1.15.0 Yes
Application oracle enterprise_manager_for_storage_management 13.4.0.0 Yes
Application oracle enterprise_manager_ops_center 12.4.0.0 Yes
Application oracle graalvm 19.3.5 Yes
Application oracle graalvm 20.3.1.2 Yes
Application oracle graalvm 21.0.0.2 Yes
Application oracle jd_edwards_enterpriseone_tools < 9.2.6.0 Yes
Application oracle jd_edwards_world_security a9.4 Yes
Application oracle mysql_server < 5.7.33 Yes
Application oracle mysql_server < 8.0.23 Yes
Application oracle nosql_database < 20.3 Yes
Application mcafee epolicy_orchestrator < 5.10.0 Yes
Application mcafee epolicy_orchestrator 5.10.0 Yes
Application mcafee epolicy_orchestrator 5.10.0 Yes
Application mcafee epolicy_orchestrator 5.10.0 Yes
Application mcafee epolicy_orchestrator 5.10.0 Yes
Application mcafee epolicy_orchestrator 5.10.0 Yes
Application mcafee epolicy_orchestrator 5.10.0 Yes
Application mcafee epolicy_orchestrator 5.10.0 Yes
Application mcafee epolicy_orchestrator 5.10.0 Yes
Application mcafee epolicy_orchestrator 5.10.0 Yes
Application mcafee epolicy_orchestrator 5.10.0 Yes
Application mcafee epolicy_orchestrator 5.10.0 Yes
Operating System fujitsu m10-1_firmware < xcp2410 Yes
Hardware fujitsu m10-1 - No
Operating System fujitsu m10-4_firmware < xcp2410 Yes
Hardware fujitsu m10-4 - No
Operating System fujitsu m10-4s_firmware < xcp2410 Yes
Hardware fujitsu m10-4s - No
Operating System fujitsu m12-1_firmware < xcp2410 Yes
Hardware fujitsu m12-1 - No
Operating System fujitsu m12-2_firmware < xcp2410 Yes
Hardware fujitsu m12-2 - No
Operating System fujitsu m12-2s_firmware < xcp2410 Yes
Hardware fujitsu m12-2s - No
Operating System fujitsu m10-1_firmware < xcp3110 Yes
Hardware fujitsu m10-1 - No
Operating System fujitsu m10-4_firmware < xcp3110 Yes
Hardware fujitsu m10-4 - No
Operating System fujitsu m10-4s_firmware < xcp3110 Yes
Hardware fujitsu m10-4s - No
Operating System fujitsu m12-1_firmware < xcp3110 Yes
Hardware fujitsu m12-1 - No
Operating System fujitsu m12-2_firmware < xcp3110 Yes
Hardware fujitsu m12-2 - No
Operating System fujitsu m12-2s_firmware < xcp3110 Yes
Hardware fujitsu m12-2s - No
Application nodejs node.js ≤ 10.12.0 Yes
Application nodejs node.js < 10.24.0 Yes
Application nodejs node.js ≤ 12.12.0 Yes
Application nodejs node.js < 12.21.0 Yes
Application nodejs node.js ≤ 14.14.0 Yes
Application nodejs node.js < 15.10.0 Yes
Application nodejs node.js 14.15.0 Yes

References