[USN-4745-1] OpenSSL vulnerabilities

Severity High
Affected Packages 12
CVEs 2

Several security issues were fixed in OpenSSL.

David Benjamin discovered that OpenSSL incorrectly handled comparing
certificates containing a EDIPartyName name type. A remote attacker could
possibly use this issue to cause OpenSSL to crash, resulting in a denial of
service. (CVE-2020-1971)

Tavis Ormandy discovered that OpenSSL incorrectly handled parsing issuer
fields. A remote attacker could possibly use this issue to cause OpenSSL to
crash, resulting in a denial of service. (CVE-2021-23841)

ID
USN-4745-1
Severity
high
URL
https://ubuntu.com/security/notices/USN-4745-1
Published
2021-02-23T19:33:18
(3 years ago)
Modified
2021-02-23T19:33:18
(3 years ago)
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:deb/ubuntu/openssl?distro=trusty ubuntu openssl < 1.0.1f-1ubuntu2.27+esm2 trusty
Affected pkg:deb/ubuntu/openssl?distro=precise ubuntu openssl < 1.0.1-4ubuntu5.45 precise
Affected pkg:deb/ubuntu/libssl1.0.0?distro=trusty ubuntu libssl1.0.0 < 1.0.1f-1ubuntu2.27+esm2 trusty
Affected pkg:deb/ubuntu/libssl1.0.0?distro=precise ubuntu libssl1.0.0 < 1.0.1-4ubuntu5.45 precise
Affected pkg:deb/ubuntu/libssl1.0.0-udeb?distro=trusty ubuntu libssl1.0.0-udeb < 1.0.1f-1ubuntu2.27+esm2 trusty
Affected pkg:deb/ubuntu/libssl1.0.0-udeb?distro=precise ubuntu libssl1.0.0-udeb < 1.0.1-4ubuntu5.45 precise
Affected pkg:deb/ubuntu/libssl-doc?distro=trusty ubuntu libssl-doc < 1.0.1f-1ubuntu2.27+esm2 trusty
Affected pkg:deb/ubuntu/libssl-doc?distro=precise ubuntu libssl-doc < 1.0.1-4ubuntu5.45 precise
Affected pkg:deb/ubuntu/libssl-dev?distro=trusty ubuntu libssl-dev < 1.0.1f-1ubuntu2.27+esm2 trusty
Affected pkg:deb/ubuntu/libssl-dev?distro=precise ubuntu libssl-dev < 1.0.1-4ubuntu5.45 precise
Affected pkg:deb/ubuntu/libcrypto1.0.0-udeb?distro=trusty ubuntu libcrypto1.0.0-udeb < 1.0.1f-1ubuntu2.27+esm2 trusty
Affected pkg:deb/ubuntu/libcrypto1.0.0-udeb?distro=precise ubuntu libcrypto1.0.0-udeb < 1.0.1-4ubuntu5.45 precise
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...