[ALAS2-2021-1721] Amazon Linux 2 2017.12 - ALAS2-2021-1721: medium priority package update for openssl
Severity
Medium
Affected Packages
18
CVEs
1
Package updates are available for Amazon Linux 2 that fix the following vulnerabilities:
CVE-2021-3712:
It was found that openssl assumed ASN.1 strings to be NUL terminated. A malicious actor may be able to force an application into calling openssl function with a specially crafted, non-NUL terminated string to deliberately hit this bug, which may result in a crash of the application, causing a Denial of Service attack, or possibly, memory disclosure. The highest threat from this vulnerability is to data confidentiality and system availability.
1995634: CVE-2021-3712 openssl: Read buffer overruns processing ASN.1 strings
- ID
- ALAS2-2021-1721
- Severity
- medium
- URL
- https://alas.aws.amazon.com/AL2/ALAS-2021-1721.html
- Published
-
2021-10-26T23:29:00
(2 years ago) - Modified
-
2021-11-04T18:05:00
(2 years ago) - Rights
- Amazon Linux Security Team
- Other Advisories
-
- ALAS-2021-1541
- ALAS2-2021-1714
- ALAS2-2024-2502
- ALPINE:CVE-2021-3712
- ALSA-2021:5226
- DSA-4963-1
- ELSA-2021-5226
- ELSA-2021-9632
- ELSA-2022-0064
- ELSA-2022-9017
- ELSA-2022-9023
- FREEBSD:7262F826-795E-11EC-8BE6-D4C9EF517024
- FREEBSD:96811D4A-04EC-11EC-9B84-D4C9EF517024
- GLSA-202209-02
- GLSA-202210-02
- MS:CVE-2021-3712
- openSUSE-SU-2021:1188-1
- openSUSE-SU-2021:1189-1
- openSUSE-SU-2021:1248-1
- openSUSE-SU-2021:1261-1
- openSUSE-SU-2021:2827-1
- openSUSE-SU-2021:2830-1
- openSUSE-SU-2021:2966-1
- openSUSE-SU-2021:2994-1
- RHSA-2021:5226
- RHSA-2022:0064
- RLSA-2021:5226
- RUSTSEC-2021-0098
- SECADV-20210824-2
- SUSE-SU-2021:2825-1
- SUSE-SU-2021:2826-1
- SUSE-SU-2021:2827-1
- SUSE-SU-2021:2829-1
- SUSE-SU-2021:2830-1
- SUSE-SU-2021:2831-1
- SUSE-SU-2021:2833-1
- SUSE-SU-2021:2852-1
- SUSE-SU-2021:2966-1
- SUSE-SU-2021:2966-2
- SUSE-SU-2021:2967-1
- SUSE-SU-2021:2968-1
- SUSE-SU-2021:2994-1
- SUSE-SU-2021:2995-1
- SUSE-SU-2021:2996-1
- SUSE-SU-2021:3019-1
- SUSE-SU-2021:3144-1
- USN-5051-1
- USN-5051-2
- USN-5051-3
- USN-5088-1
Source | # ID | Name | URL |
---|---|---|---|
CVE | CVE-2021-3712 | http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3712 |
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:rpm/amazonlinux/openssl?arch=x86_64&distro=amazonlinux-2 | amazonlinux | openssl | < 1.0.2k-19.amzn2.0.8 | amazonlinux-2 | x86_64 | |
Affected | pkg:rpm/amazonlinux/openssl?arch=i686&distro=amazonlinux-2 | amazonlinux | openssl | < 1.0.2k-19.amzn2.0.8 | amazonlinux-2 | i686 | |
Affected | pkg:rpm/amazonlinux/openssl?arch=aarch64&distro=amazonlinux-2 | amazonlinux | openssl | < 1.0.2k-19.amzn2.0.8 | amazonlinux-2 | aarch64 | |
Affected | pkg:rpm/amazonlinux/openssl-static?arch=x86_64&distro=amazonlinux-2 | amazonlinux | openssl-static | < 1.0.2k-19.amzn2.0.8 | amazonlinux-2 | x86_64 | |
Affected | pkg:rpm/amazonlinux/openssl-static?arch=i686&distro=amazonlinux-2 | amazonlinux | openssl-static | < 1.0.2k-19.amzn2.0.8 | amazonlinux-2 | i686 | |
Affected | pkg:rpm/amazonlinux/openssl-static?arch=aarch64&distro=amazonlinux-2 | amazonlinux | openssl-static | < 1.0.2k-19.amzn2.0.8 | amazonlinux-2 | aarch64 | |
Affected | pkg:rpm/amazonlinux/openssl-perl?arch=x86_64&distro=amazonlinux-2 | amazonlinux | openssl-perl | < 1.0.2k-19.amzn2.0.8 | amazonlinux-2 | x86_64 | |
Affected | pkg:rpm/amazonlinux/openssl-perl?arch=i686&distro=amazonlinux-2 | amazonlinux | openssl-perl | < 1.0.2k-19.amzn2.0.8 | amazonlinux-2 | i686 | |
Affected | pkg:rpm/amazonlinux/openssl-perl?arch=aarch64&distro=amazonlinux-2 | amazonlinux | openssl-perl | < 1.0.2k-19.amzn2.0.8 | amazonlinux-2 | aarch64 | |
Affected | pkg:rpm/amazonlinux/openssl-libs?arch=x86_64&distro=amazonlinux-2 | amazonlinux | openssl-libs | < 1.0.2k-19.amzn2.0.8 | amazonlinux-2 | x86_64 | |
Affected | pkg:rpm/amazonlinux/openssl-libs?arch=i686&distro=amazonlinux-2 | amazonlinux | openssl-libs | < 1.0.2k-19.amzn2.0.8 | amazonlinux-2 | i686 | |
Affected | pkg:rpm/amazonlinux/openssl-libs?arch=aarch64&distro=amazonlinux-2 | amazonlinux | openssl-libs | < 1.0.2k-19.amzn2.0.8 | amazonlinux-2 | aarch64 | |
Affected | pkg:rpm/amazonlinux/openssl-devel?arch=x86_64&distro=amazonlinux-2 | amazonlinux | openssl-devel | < 1.0.2k-19.amzn2.0.8 | amazonlinux-2 | x86_64 | |
Affected | pkg:rpm/amazonlinux/openssl-devel?arch=i686&distro=amazonlinux-2 | amazonlinux | openssl-devel | < 1.0.2k-19.amzn2.0.8 | amazonlinux-2 | i686 | |
Affected | pkg:rpm/amazonlinux/openssl-devel?arch=aarch64&distro=amazonlinux-2 | amazonlinux | openssl-devel | < 1.0.2k-19.amzn2.0.8 | amazonlinux-2 | aarch64 | |
Affected | pkg:rpm/amazonlinux/openssl-debuginfo?arch=x86_64&distro=amazonlinux-2 | amazonlinux | openssl-debuginfo | < 1.0.2k-19.amzn2.0.8 | amazonlinux-2 | x86_64 | |
Affected | pkg:rpm/amazonlinux/openssl-debuginfo?arch=i686&distro=amazonlinux-2 | amazonlinux | openssl-debuginfo | < 1.0.2k-19.amzn2.0.8 | amazonlinux-2 | i686 | |
Affected | pkg:rpm/amazonlinux/openssl-debuginfo?arch=aarch64&distro=amazonlinux-2 | amazonlinux | openssl-debuginfo | < 1.0.2k-19.amzn2.0.8 | amazonlinux-2 | aarch64 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |