CVE-2021-23840
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output length argument in some cases where the input length is close to the maximum permissable length for an integer on the platform. In such cases the return value from the function call will be 1 (indicating success), but the output length value will be negative. This could cause applications to behave incorrectly or crash. OpenSSL versions 1.1.1i and below are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1j. OpenSSL versions 1.0.2x and below are affected by this issue. However OpenSSL 1.0.2 is out of support and no longer receiving public updates. Premium support customers of OpenSSL 1.0.2 should upgrade to 1.0.2y. Other users should upgrade to 1.1.1j. Fixed in OpenSSL 1.1.1j (Affected 1.1.1-1.1.1i). Fixed in OpenSSL 1.0.2y (Affected 1.0.2-1.0.2x).
Affected (55)
Products: Openssl: Openssl · Debian: Debian Linux · Tenable: Log Correlation Engine, Nessus Network Monitor · +4 more
Show all products
Openssl: Openssl · Debian: Debian Linux · Tenable: Log Correlation Engine, Nessus Network Monitor · Oracle: Business Intelligence, Communications Cloud Native Core Policy, Enterprise Manager For Storage Management, Enterprise Manager Ops Center, Graalvm, Jd Edwards Enterpriseone Tools, Jd Edwards World Security, Mysql Server, Nosql Database · Mcafee: Epolicy Orchestrator · Fujitsu: M10 1 Firmware, M10 4 Firmware, M10 4s Firmware, M12 1 Firmware, M12 2 Firmware, M12 2s Firmware · Nodejs: Node.js
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.0 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 6.0.8 | |
| Version 5.11.0 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 12.2.1.3.0 | |
| Version 1.15.0 | |
| Version 13.4.0.0 | |
| Version 12.4.0.0 | |
| Version 19.3.5 | |
| Before 9.2.6.0 | |
| Version a9.4 | |
| Before 5.7.33 | |
| Before 20.3 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.10.0 |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before xcp2410 |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before xcp2410 |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before xcp2410 |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before xcp2410 |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before xcp2410 |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before xcp2410 |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before xcp3110 |
| Running on/with | Platform Versions |
|---|---|
Fujitsu M10 1 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before xcp3110 |
| Running on/with | Platform Versions |
|---|---|
Fujitsu M10 4 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before xcp3110 |
| Running on/with | Platform Versions |
|---|---|
Fujitsu M10 4s | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before xcp3110 |
| Running on/with | Platform Versions |
|---|---|
Fujitsu M12 1 | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before xcp3110 |
| Running on/with | Platform Versions |
|---|---|
Fujitsu M12 2 | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before xcp3110 |
| Running on/with | Platform Versions |
|---|---|
Fujitsu M12 2s | All versions |
References (40)
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
Source: openssl-security@openssl.org
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
Source: openssl-security@openssl.org
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
PatchThird Party Advisory
Source: openssl-security@openssl.org
PatchThird Party Advisory
Source: openssl-security@openssl.org
PatchThird Party Advisory
Source: openssl-security@openssl.org
PatchThird Party Advisory
Source: openssl-security@openssl.org
PatchThird Party Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.