[USN-5051-2] OpenSSL vulnerability
Severity
Medium
Affected Packages
8
CVEs
1
OpenSSL could be made to crash or expose sensitive information if it received a specially crafted ASN.1 string.
USN-5051-1 fixed a vulnerability in OpenSSL. This update provides
the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.
Original advisory details:
Ingo Schwarze discovered that OpenSSL incorrectly handled certain ASN.1
strings. A remote attacker could use this issue to cause OpenSSL to crash,
resulting in a denial of service, or possibly obtain sensitive information.
(CVE-2021-3712)
Package | Affected Version |
---|---|
pkg:deb/ubuntu/openssl?distro=xenial | < 1.0.2g-1ubuntu4.20+esm1 |
pkg:deb/ubuntu/openssl?distro=trusty | < 1.0.1f-1ubuntu2.27+esm3 |
pkg:deb/ubuntu/libssl1.0.0?distro=xenial | < 1.0.2g-1ubuntu4.20+esm1 |
pkg:deb/ubuntu/libssl1.0.0?distro=trusty | < 1.0.1f-1ubuntu2.27+esm3 |
pkg:deb/ubuntu/libssl-doc?distro=xenial | < 1.0.2g-1ubuntu4.20+esm1 |
pkg:deb/ubuntu/libssl-doc?distro=trusty | < 1.0.1f-1ubuntu2.27+esm3 |
pkg:deb/ubuntu/libssl-dev?distro=xenial | < 1.0.2g-1ubuntu4.20+esm1 |
pkg:deb/ubuntu/libssl-dev?distro=trusty | < 1.0.1f-1ubuntu2.27+esm3 |
- ID
- USN-5051-2
- Severity
- medium
- URL
- https://ubuntu.com/security/notices/USN-5051-2
- Published
-
2021-08-26T12:40:18
(3 years ago) - Modified
-
2021-08-26T12:40:18
(3 years ago) - Other Advisories
-
- ALAS-2021-1541
- ALAS2-2021-1714
- ALAS2-2021-1721
- ALAS2-2024-2502
- ALPINE:CVE-2021-3712
- ALSA-2021:5226
- DSA-4963-1
- ELSA-2021-5226
- ELSA-2021-9632
- ELSA-2022-0064
- ELSA-2022-9017
- ELSA-2022-9023
- FREEBSD:7262F826-795E-11EC-8BE6-D4C9EF517024
- FREEBSD:96811D4A-04EC-11EC-9B84-D4C9EF517024
- GLSA-202209-02
- GLSA-202210-02
- MS:CVE-2021-3712
- openSUSE-SU-2021:1188-1
- openSUSE-SU-2021:1189-1
- openSUSE-SU-2021:1248-1
- openSUSE-SU-2021:1261-1
- openSUSE-SU-2021:2827-1
- openSUSE-SU-2021:2830-1
- openSUSE-SU-2021:2966-1
- openSUSE-SU-2021:2994-1
- RHSA-2021:5226
- RHSA-2022:0064
- RLSA-2021:5226
- RUSTSEC-2021-0098
- SECADV-20210824-2
- SUSE-SU-2021:2825-1
- SUSE-SU-2021:2826-1
- SUSE-SU-2021:2827-1
- SUSE-SU-2021:2829-1
- SUSE-SU-2021:2830-1
- SUSE-SU-2021:2831-1
- SUSE-SU-2021:2833-1
- SUSE-SU-2021:2852-1
- SUSE-SU-2021:2966-1
- SUSE-SU-2021:2966-2
- SUSE-SU-2021:2967-1
- SUSE-SU-2021:2968-1
- SUSE-SU-2021:2994-1
- SUSE-SU-2021:2995-1
- SUSE-SU-2021:2996-1
- SUSE-SU-2021:3019-1
- SUSE-SU-2021:3144-1
- USN-5051-1
- USN-5051-3
- USN-5088-1
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:deb/ubuntu/openssl?distro=xenial | ubuntu | openssl | < 1.0.2g-1ubuntu4.20+esm1 | xenial | ||
Affected | pkg:deb/ubuntu/openssl?distro=trusty | ubuntu | openssl | < 1.0.1f-1ubuntu2.27+esm3 | trusty | ||
Affected | pkg:deb/ubuntu/libssl1.0.0?distro=xenial | ubuntu | libssl1.0.0 | < 1.0.2g-1ubuntu4.20+esm1 | xenial | ||
Affected | pkg:deb/ubuntu/libssl1.0.0?distro=trusty | ubuntu | libssl1.0.0 | < 1.0.1f-1ubuntu2.27+esm3 | trusty | ||
Affected | pkg:deb/ubuntu/libssl-doc?distro=xenial | ubuntu | libssl-doc | < 1.0.2g-1ubuntu4.20+esm1 | xenial | ||
Affected | pkg:deb/ubuntu/libssl-doc?distro=trusty | ubuntu | libssl-doc | < 1.0.1f-1ubuntu2.27+esm3 | trusty | ||
Affected | pkg:deb/ubuntu/libssl-dev?distro=xenial | ubuntu | libssl-dev | < 1.0.2g-1ubuntu4.20+esm1 | xenial | ||
Affected | pkg:deb/ubuntu/libssl-dev?distro=trusty | ubuntu | libssl-dev | < 1.0.1f-1ubuntu2.27+esm3 | trusty |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |