CVE-2021-3618: High severity F5 Nginx vulnerability
ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to victim's traffic at the TCP/IP layer can redirect traffic from one subdomain to another, resulting in a valid TLS session. This breaks the authentication of TLS and cross-protocol attacks may be possible where the behavior of one protocol service may compromise the other at the application layer.
Other sources
As per the researchers:
ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. Attackers can redirect traffic from one subdomain to another, resulting in a valid TLS session. This breaks the authentication of TLS and cross-protocol attacks may be possible where the behavior of one protocol service may compromise the other at the application layer.
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is ALPACA vulnerability (CVE-2021-3618)?
ALPACA is an application layer protocol content confusion attack that exploits TLS servers implementing different protocols but using compatible certificates.
What is the severity of CVE-2021-3618?
The severity of CVE-2021-3618 is medium.
Which software is affected by CVE-2021-3618?
The software affected by CVE-2021-3618 include nginx, sendmail, and vsftpd.
How do I fix CVE-2021-3618 on Debian?
To fix CVE-2021-3618 on Debian, update the affected software to the specified versions: nginx (1.14.2-2+deb10u5, 1.18.0-6.1+deb11u3, 1.22.1-9, 1.24.0-1), sendmail (8.17.1.9-2, 8.17.2-1).
How do I fix CVE-2021-3618 on Red Hat?
To fix CVE-2021-3618 on Red Hat, update the affected software to the specified versions: nginx (1.21.0), sendmail (8.17), vsftpd (3.0.4).
How do I fix CVE-2021-3618 on Ubuntu?
To fix CVE-2021-3618 on Ubuntu, update the affected software to the specified versions: nginx (upstream: 1.21.0, bionic: 1.14.0-0ubuntu1.10, focal: 1.18.0-0ubuntu1.3, xenial: 1.10.3-0ubuntu0.16.04.5+, impish: 1.18.0-6ubuntu11.1, jammy: 1.18.0-6ubuntu14.1), sendmail (upstream: 8.16.1-1), vsftpd (upstream: 3.0.4, focal: 3.0.5-0ubuntu0.20.04.1).