Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-23841


The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash value based on the issuer and serial number data contained within an X509 certificate. However it fails to correctly handle any errors that may occur while parsing the issuer field (which might occur if the issuer field is maliciously constructed). This may subsequently result in a NULL pointer deref and a crash leading to a potential denial of service attack. The function X509_issuer_and_serial_hash() is never directly called by OpenSSL itself so applications are only vulnerable if they use this function directly and they use it on certificates that may have been obtained from untrusted sources. OpenSSL versions 1.1.1i and below are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1j. OpenSSL versions 1.0.2x and below are affected by this issue. However OpenSSL 1.0.2 is out of support and no longer receiving public updates. Premium support customers of OpenSSL 1.0.2 should upgrade to 1.0.2y. Other users should upgrade to 1.1.1j. Fixed in OpenSSL 1.1.1j (Affected 1.1.1-1.1.1i). Fixed in OpenSSL 1.0.2y (Affected 1.0.2-1.0.2x).


Published

2021-02-16T17:15:13.377

Last Modified

2024-11-21T05:51:55.460

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.9 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-476

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application openssl openssl < 1.0.2y Yes
Application openssl openssl < 1.1.1j Yes
Operating System debian debian_linux 10.0 Yes
Application tenable nessus_network_monitor 5.11.0 Yes
Application tenable nessus_network_monitor 5.11.1 Yes
Application tenable nessus_network_monitor 5.12.0 Yes
Application tenable nessus_network_monitor 5.12.1 Yes
Application tenable nessus_network_monitor 5.13.0 Yes
Application tenable tenable.sc ≤ 5.17.0 Yes
Application apple safari < 14.1.1 Yes
Operating System apple ipados < 14.6 Yes
Operating System apple iphone_os < 14.6 Yes
Operating System apple macos < 11.4 Yes
Application netapp oncommand_insight - Yes
Application netapp oncommand_workflow_automation - Yes
Application netapp snapcenter - Yes
Application oracle business_intelligence 5.5.0.0.0 Yes
Application oracle business_intelligence 5.9.0.0.0 Yes
Application oracle business_intelligence 12.2.1.3.0 Yes
Application oracle business_intelligence 12.2.1.4.0 Yes
Application oracle communications_cloud_native_core_policy 1.15.0 Yes
Application oracle enterprise_manager_for_storage_management 13.4.0.0 Yes
Application oracle enterprise_manager_ops_center 12.4.0.0 Yes
Application oracle essbase 21.2 Yes
Application oracle graalvm 19.3.5 Yes
Application oracle graalvm 20.3.1.2 Yes
Application oracle graalvm 21.0.0.2 Yes
Application oracle jd_edwards_world_security a9.4 Yes
Application oracle mysql_enterprise_monitor < 8.0.23 Yes
Application oracle mysql_server < 5.7.33 Yes
Application oracle mysql_server < 8.0.23 Yes
Application oracle peoplesoft_enterprise_peopletools 8.57 Yes
Application oracle peoplesoft_enterprise_peopletools 8.58 Yes
Application oracle peoplesoft_enterprise_peopletools 8.59 Yes
Application oracle zfs_storage_appliance_kit 8.8 Yes
Application siemens sinec_ins < 1.0 Yes
Application siemens sinec_ins 1.0 Yes
Application siemens sinec_ins 1.0 Yes

References