← Back

CVE-2021-23840

nvd nist
Published: Feb 16, 2021Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output length argument in some cases where the input length is close to the maximum permissable length for an integer on the platform. In such cases the return value from the function call will be 1 (indicating success), but the output length value will be negative. This could cause applications to behave incorrectly or crash. OpenSSL versions 1.1.1i and below are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1j. OpenSSL versions 1.0.2x and below are affected by this issue. However OpenSSL 1.0.2 is out of support and no longer receiving public updates. Premium support customers of OpenSSL 1.0.2 should upgrade to 1.0.2y. Other users should upgrade to 1.1.1j. Fixed in OpenSSL 1.1.1j (Affected 1.1.1-1.1.1i). Fixed in OpenSSL 1.0.2y (Affected 1.0.2-1.0.2x).

Affected (55)

Show all products
1 product
Openssl
1 product
Debian Linux
2 products
Log Correlation Engine
Nessus Network Monitor
9 products
Business Intelligence
Enterprise Manager Ops Center
Graalvm
Jd Edwards Enterpriseone Tools
Jd Edwards World Security
Mysql Server
Nosql Database
1 product
Epolicy Orchestrator
6 products
M10 1 Firmware
M10 4 Firmware
M10 4s Firmware
M12 1 Firmware
M12 2 Firmware
M12 2s Firmware
1 product
Node.js
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Openssl
From 1.0.2 to 1.0.2y
From 1.1.1 to 1.1.1j
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 10.0
Configuration C
6 vulnerable
Vulnerable SoftwareAffected Versions
Before 6.0.8
Tenable
Version 5.11.0
Version 5.11.1
Version 5.12.0
Version 5.12.1
Version 5.13.0
Configuration D
15 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 12.2.1.3.0
Version 12.2.1.4.0
Version 5.5.0.0.0
Version 5.9.0.0.0
Version 1.15.0
Version 13.4.0.0
Version 12.4.0.0
Oracle
Version 19.3.5
Version 20.3.1.2
Version 21.0.0.2
Before 9.2.6.0
Version a9.4
Oracle
Before 5.7.33
From 8.0.15 to 8.0.23
Before 20.3
Configuration E
12 vulnerable
Vulnerable SoftwareAffected Versions
Mcafee
Before 5.10.0
Version 5.10.0
Version 5.10.0 update_10
Version 5.10.0 update_1
Version 5.10.0 update_2
Version 5.10.0 update_3
Version 5.10.0 update_4
Version 5.10.0 update_5
Version 5.10.0 update_6
Version 5.10.0 update_7
Version 5.10.0 update_8
Version 5.10.0 update_9
Configuration F
1 vulnerable
Vulnerable SoftwareAffected Versions
Before xcp2410
Configuration G
1 vulnerable
Vulnerable SoftwareAffected Versions
Before xcp2410
Configuration H
1 vulnerable
Vulnerable SoftwareAffected Versions
Before xcp2410
Configuration I
1 vulnerable
Vulnerable SoftwareAffected Versions
Before xcp2410
Configuration J
1 vulnerable
Vulnerable SoftwareAffected Versions
Before xcp2410
Configuration K
1 vulnerable
Vulnerable SoftwareAffected Versions
Before xcp2410
Configuration L
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before xcp3110
Running on/withPlatform Versions
Fujitsu
M10 1
All versions
Configuration M
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before xcp3110
Running on/withPlatform Versions
Fujitsu
M10 4
All versions
Configuration N
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before xcp3110
Running on/withPlatform Versions
Fujitsu
M10 4s
All versions
Configuration O
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before xcp3110
Running on/withPlatform Versions
Fujitsu
M12 1
All versions
Configuration P
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before xcp3110
Running on/withPlatform Versions
Fujitsu
M12 2
All versions
Configuration Q
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before xcp3110
Running on/withPlatform Versions
Fujitsu
M12 2s
All versions
Configuration R
7 vulnerable
Vulnerable SoftwareAffected Versions
Nodejs
From 10.0.0 to 10.12.0
From 12.0.0 to 12.12.0
From 14.0.0 to 14.14.0
From 15.0.0 to 15.10.0
From 10.13.0 to 10.24.0
From 12.13.0 to 12.21.0
Version 14.15.0

References (40)

Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
Vendor Advisory
Source: openssl-security@openssl.org
PatchThird Party Advisory
Source: openssl-security@openssl.org
PatchThird Party Advisory
Source: openssl-security@openssl.org
PatchThird Party Advisory
Source: openssl-security@openssl.org
PatchThird Party Advisory
Source: openssl-security@openssl.org
PatchThird Party Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.