[ALAS2-2021-1622] Amazon Linux 2 2017.12 - ALAS2-2021-1622: important priority package update for openssl11

Severity Important
Affected Packages 15
CVEs 2

Package updates are available for Amazon Linux 2 that fix the following vulnerabilities:
CVE-2021-3450:
A flaw was found in openssl. The flag that enables additional security checks of certificates present in a certificate chain was not enabled allowing a confirmation step to verify that certificates in the chain are valid CA certificates is bypassed. The highest threat from this vulnerability is to data confidentiality and integrity.
1941547: CVE-2021-3450 openssl: CA certificate check bypass with X509_V_FLAG_X509_STRICT

CVE-2021-3449:
A flaw was found in openssl. A server crash and denial of service attack could occur if a client sends a TLSv1.2 renegotiation ClientHello and omits the signature_algorithms extension but includes a signature_algorithms_cert extension. The highest threat from this vulnerability is to system availability.
1941554: CVE-2021-3449 openssl: NULL pointer deref in signature_algorithms processing

Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/amazonlinux/openssl11?arch=x86_64&distro=amazonlinux-2 amazonlinux openssl11 < 1.1.1g-12.amzn2.0.3 amazonlinux-2 x86_64
Affected pkg:rpm/amazonlinux/openssl11?arch=i686&distro=amazonlinux-2 amazonlinux openssl11 < 1.1.1g-12.amzn2.0.3 amazonlinux-2 i686
Affected pkg:rpm/amazonlinux/openssl11?arch=aarch64&distro=amazonlinux-2 amazonlinux openssl11 < 1.1.1g-12.amzn2.0.3 amazonlinux-2 aarch64
Affected pkg:rpm/amazonlinux/openssl11-static?arch=x86_64&distro=amazonlinux-2 amazonlinux openssl11-static < 1.1.1g-12.amzn2.0.3 amazonlinux-2 x86_64
Affected pkg:rpm/amazonlinux/openssl11-static?arch=i686&distro=amazonlinux-2 amazonlinux openssl11-static < 1.1.1g-12.amzn2.0.3 amazonlinux-2 i686
Affected pkg:rpm/amazonlinux/openssl11-static?arch=aarch64&distro=amazonlinux-2 amazonlinux openssl11-static < 1.1.1g-12.amzn2.0.3 amazonlinux-2 aarch64
Affected pkg:rpm/amazonlinux/openssl11-libs?arch=x86_64&distro=amazonlinux-2 amazonlinux openssl11-libs < 1.1.1g-12.amzn2.0.3 amazonlinux-2 x86_64
Affected pkg:rpm/amazonlinux/openssl11-libs?arch=i686&distro=amazonlinux-2 amazonlinux openssl11-libs < 1.1.1g-12.amzn2.0.3 amazonlinux-2 i686
Affected pkg:rpm/amazonlinux/openssl11-libs?arch=aarch64&distro=amazonlinux-2 amazonlinux openssl11-libs < 1.1.1g-12.amzn2.0.3 amazonlinux-2 aarch64
Affected pkg:rpm/amazonlinux/openssl11-devel?arch=x86_64&distro=amazonlinux-2 amazonlinux openssl11-devel < 1.1.1g-12.amzn2.0.3 amazonlinux-2 x86_64
Affected pkg:rpm/amazonlinux/openssl11-devel?arch=i686&distro=amazonlinux-2 amazonlinux openssl11-devel < 1.1.1g-12.amzn2.0.3 amazonlinux-2 i686
Affected pkg:rpm/amazonlinux/openssl11-devel?arch=aarch64&distro=amazonlinux-2 amazonlinux openssl11-devel < 1.1.1g-12.amzn2.0.3 amazonlinux-2 aarch64
Affected pkg:rpm/amazonlinux/openssl11-debuginfo?arch=x86_64&distro=amazonlinux-2 amazonlinux openssl11-debuginfo < 1.1.1g-12.amzn2.0.3 amazonlinux-2 x86_64
Affected pkg:rpm/amazonlinux/openssl11-debuginfo?arch=i686&distro=amazonlinux-2 amazonlinux openssl11-debuginfo < 1.1.1g-12.amzn2.0.3 amazonlinux-2 i686
Affected pkg:rpm/amazonlinux/openssl11-debuginfo?arch=aarch64&distro=amazonlinux-2 amazonlinux openssl11-debuginfo < 1.1.1g-12.amzn2.0.3 amazonlinux-2 aarch64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...