← Back

CVE-2021-23841

nvd nist
Published: Feb 16, 2021Modified: Jun 17, 2026

JSON object

Loading...
5.9
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 2.2 / Impact: 3.6
Source: NVD

Description

The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash value based on the issuer and serial number data contained within an X509 certificate. However it fails to correctly handle any errors that may occur while parsing the issuer field (which might occur if the issuer field is maliciously constructed). This may subsequently result in a NULL pointer deref and a crash leading to a potential denial of service attack. The function X509_issuer_and_serial_hash() is never directly called by OpenSSL itself so applications are only vulnerable if they use this function directly and they use it on certificates that may have been obtained from untrusted sources. OpenSSL versions 1.1.1i and below are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1j. OpenSSL versions 1.0.2x and below are affected by this issue. However OpenSSL 1.0.2 is out of support and no longer receiving public updates. Premium support customers of OpenSSL 1.0.2 should upgrade to 1.0.2y. Other users should upgrade to 1.1.1j. Fixed in OpenSSL 1.1.1j (Affected 1.1.1-1.1.1i). Fixed in OpenSSL 1.0.2y (Affected 1.0.2-1.0.2x).

Affected (38)

Show all products
1 product
Openssl
1 product
Debian Linux
2 products
Nessus Network Monitor
Tenable.sc
4 products
Ipados
Iphone Os
Macos
Safari
3 products
Oncommand Insight
Oncommand Workflow Automation
Snapcenter
11 products
Business Intelligence
Enterprise Manager Ops Center
Essbase
Graalvm
Jd Edwards World Security
Mysql Enterprise Monitor
Mysql Server
Peoplesoft Enterprise Peopletools
Zfs Storage Appliance Kit
1 product
Sinec Ins
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Openssl
From 1.0.2 to 1.0.2y
From 1.1.1 to 1.1.1j
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 10.0
Configuration C
6 vulnerable
Vulnerable SoftwareAffected Versions
Tenable
Version 5.11.0
Version 5.11.1
Version 5.12.0
Version 5.12.1
Version 5.13.0
From 5.13.0 to 5.17.0
Configuration D
4 vulnerable
Vulnerable SoftwareAffected Versions
Before 14.6
Before 14.6
From 11.1 to 11.4
Before 14.1.1
Configuration E
3 vulnerable
Vulnerable SoftwareAffected Versions
All versions
All versions
All versions
Configuration F
19 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 12.2.1.3.0
Version 12.2.1.4.0
Version 5.5.0.0.0
Version 5.9.0.0.0
Version 1.15.0
Version 13.4.0.0
Version 12.4.0.0
Version 21.2
Oracle
Version 19.3.5
Version 20.3.1.2
Version 21.0.0.2
Version a9.4
Before 8.0.23
Oracle
Before 5.7.33
From 8.0.15 to 8.0.23
Oracle
Version 8.57
Version 8.58
Version 8.59
Version 8.8
Configuration G
3 vulnerable
Vulnerable SoftwareAffected Versions
Siemens
Before 1.0
Version 1.0
Version 1.0 sp1

References (44)

Source: openssl-security@openssl.org
Mailing ListThird Party Advisory
Source: openssl-security@openssl.org
Mailing ListThird Party Advisory
Source: openssl-security@openssl.org
Mailing ListThird Party Advisory
Source: openssl-security@openssl.org
PatchThird Party Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
Vendor Advisory
Source: openssl-security@openssl.org
PatchThird Party Advisory
Source: openssl-security@openssl.org
PatchThird Party Advisory
Source: openssl-security@openssl.org
PatchThird Party Advisory
Source: openssl-security@openssl.org
PatchThird Party Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.