[USN-5051-1] OpenSSL vulnerabilities
Severity
High
Affected Packages
12
CVEs
2
Several security issues were fixed in OpenSSL.
John Ouyang discovered that OpenSSL incorrectly handled decrypting SM2
data. A remote attacker could use this issue to cause applications using
OpenSSL to crash, resulting in a denial of service, or possibly change
application behaviour. (CVE-2021-3711)
Ingo Schwarze discovered that OpenSSL incorrectly handled certain ASN.1
strings. A remote attacker could use this issue to cause OpenSSL to crash,
resulting in a denial of service, or possibly obtain sensitive information.
(CVE-2021-3712)
Package | Affected Version |
---|---|
pkg:deb/ubuntu/openssl?distro=hirsute | < 1.1.1j-1ubuntu3.5 |
pkg:deb/ubuntu/openssl?distro=focal | < 1.1.1f-1ubuntu2.8 |
pkg:deb/ubuntu/openssl?distro=bionic | < 1.1.1-1ubuntu2.1~18.04.13 |
pkg:deb/ubuntu/libssl1.1?distro=hirsute | < 1.1.1j-1ubuntu3.5 |
pkg:deb/ubuntu/libssl1.1?distro=focal | < 1.1.1f-1ubuntu2.8 |
pkg:deb/ubuntu/libssl1.1?distro=bionic | < 1.1.1-1ubuntu2.1~18.04.13 |
pkg:deb/ubuntu/libssl-doc?distro=hirsute | < 1.1.1j-1ubuntu3.5 |
pkg:deb/ubuntu/libssl-doc?distro=focal | < 1.1.1f-1ubuntu2.8 |
pkg:deb/ubuntu/libssl-doc?distro=bionic | < 1.1.1-1ubuntu2.1~18.04.13 |
pkg:deb/ubuntu/libssl-dev?distro=hirsute | < 1.1.1j-1ubuntu3.5 |
pkg:deb/ubuntu/libssl-dev?distro=focal | < 1.1.1f-1ubuntu2.8 |
pkg:deb/ubuntu/libssl-dev?distro=bionic | < 1.1.1-1ubuntu2.1~18.04.13 |
- ID
- USN-5051-1
- Severity
- high
- URL
- https://ubuntu.com/security/notices/USN-5051-1
- Published
-
2021-08-24T15:26:39
(3 years ago) - Modified
-
2021-08-24T15:26:39
(3 years ago) - Other Advisories
-
- ALAS-2021-1541
- ALAS2-2021-1714
- ALAS2-2021-1721
- ALAS2-2024-2502
- ALPINE:CVE-2021-3711
- ALPINE:CVE-2021-3712
- ALSA-2021:5226
- DSA-4963-1
- ELSA-2021-5226
- ELSA-2021-9632
- ELSA-2022-0064
- ELSA-2022-9017
- ELSA-2022-9023
- FREEBSD:7262F826-795E-11EC-8BE6-D4C9EF517024
- FREEBSD:96811D4A-04EC-11EC-9B84-D4C9EF517024
- FREEBSD:C9387E4D-2F5F-11EC-8BE6-D4C9EF517024
- GLSA-202209-02
- GLSA-202210-02
- MS:CVE-2021-3711
- MS:CVE-2021-3712
- openSUSE-SU-2021:1188-1
- openSUSE-SU-2021:1189-1
- openSUSE-SU-2021:1248-1
- openSUSE-SU-2021:1261-1
- openSUSE-SU-2021:2827-1
- openSUSE-SU-2021:2830-1
- openSUSE-SU-2021:2966-1
- openSUSE-SU-2021:2994-1
- RHSA-2021:5226
- RHSA-2022:0064
- RLSA-2021:5226
- RUSTSEC-2021-0097
- RUSTSEC-2021-0098
- SECADV-20210824-1
- SECADV-20210824-2
- SUSE-SU-2021:2825-1
- SUSE-SU-2021:2826-1
- SUSE-SU-2021:2827-1
- SUSE-SU-2021:2829-1
- SUSE-SU-2021:2830-1
- SUSE-SU-2021:2831-1
- SUSE-SU-2021:2833-1
- SUSE-SU-2021:2852-1
- SUSE-SU-2021:2966-1
- SUSE-SU-2021:2966-2
- SUSE-SU-2021:2967-1
- SUSE-SU-2021:2968-1
- SUSE-SU-2021:2994-1
- SUSE-SU-2021:2995-1
- SUSE-SU-2021:2996-1
- SUSE-SU-2021:3019-1
- SUSE-SU-2021:3144-1
- SUSE-SU-2022:0751-1
- SUSE-SU-2022:1396-1
- SUSE-SU-2022:2134-1
- SUSE-SU-2022:3676-1
- SUSE-SU-2022:4428-1
- SUSE-SU-2022:4437-1
- SUSE-SU-2022:4439-1
- SUSE-SU-2024:0191-1
- SUSE-SU-2024:0196-1
- USN-5051-2
- USN-5051-3
- USN-5088-1
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:deb/ubuntu/openssl?distro=hirsute | ubuntu | openssl | < 1.1.1j-1ubuntu3.5 | hirsute | ||
Affected | pkg:deb/ubuntu/openssl?distro=focal | ubuntu | openssl | < 1.1.1f-1ubuntu2.8 | focal | ||
Affected | pkg:deb/ubuntu/openssl?distro=bionic | ubuntu | openssl | < 1.1.1-1ubuntu2.1~18.04.13 | bionic | ||
Affected | pkg:deb/ubuntu/libssl1.1?distro=hirsute | ubuntu | libssl1.1 | < 1.1.1j-1ubuntu3.5 | hirsute | ||
Affected | pkg:deb/ubuntu/libssl1.1?distro=focal | ubuntu | libssl1.1 | < 1.1.1f-1ubuntu2.8 | focal | ||
Affected | pkg:deb/ubuntu/libssl1.1?distro=bionic | ubuntu | libssl1.1 | < 1.1.1-1ubuntu2.1~18.04.13 | bionic | ||
Affected | pkg:deb/ubuntu/libssl-doc?distro=hirsute | ubuntu | libssl-doc | < 1.1.1j-1ubuntu3.5 | hirsute | ||
Affected | pkg:deb/ubuntu/libssl-doc?distro=focal | ubuntu | libssl-doc | < 1.1.1f-1ubuntu2.8 | focal | ||
Affected | pkg:deb/ubuntu/libssl-doc?distro=bionic | ubuntu | libssl-doc | < 1.1.1-1ubuntu2.1~18.04.13 | bionic | ||
Affected | pkg:deb/ubuntu/libssl-dev?distro=hirsute | ubuntu | libssl-dev | < 1.1.1j-1ubuntu3.5 | hirsute | ||
Affected | pkg:deb/ubuntu/libssl-dev?distro=focal | ubuntu | libssl-dev | < 1.1.1f-1ubuntu2.8 | focal | ||
Affected | pkg:deb/ubuntu/libssl-dev?distro=bionic | ubuntu | libssl-dev | < 1.1.1-1ubuntu2.1~18.04.13 | bionic |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |