CVE-2021-41581: Medium severity OpenBSD LibreSSL vulnerability
Published Sep 24, 2021
·Updated
x509constraintsparsemailbox in lib/libcrypto/x509/x509constraints.c in LibreSSL through 3.4.0 has a stack-based buffer over-read. When the input exceeds DOMAINPARTMAXLEN, the buffer lacks '\0' termination.
Affected Software
1 affected component
OpenBSD LibreSSL<=3.4.0
Remediation
Patch Available
Event History
Sep 24, 2021
CVE Published
via MITRE·02:12 AM
Data Sourced
via MITRE·02:12 AM
Description
Data Sourced
via NVD·03:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-41581.
2
What is the severity of CVE-2021-41581?
The severity of CVE-2021-41581 is medium with a severity value of 5.5.
3
What is the affected software?
The affected software is Openbsd Libressl up to and including version 3.4.0.
4
What is the description of CVE-2021-41581?
CVE-2021-41581 is a stack-based buffer over-read vulnerability in x509_constraints_parse_mailbox function in Libressl.
5
Is there a fix available for CVE-2021-41581?
Yes, the fix for CVE-2021-41581 is to update to a version of Libressl that is not affected by the vulnerability.