CVE-2021-46880: Critical severity libressl vulnerability
Published Apr 14, 2023
·Updated
x509/x509verify.c in LibreSSL before 3.4.2, and OpenBSD before 7.0 errata 006, allows authentication bypass because an error for an unverified certificate chain is sometimes discarded.
Affected Software
2 affected components
OpenBSD LibreSSL<3.4.2
OpenBSD OpenBSD<7.0
Remediation
Event History
Apr 14, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Apr 15, 2023
Data Sourced
via NVD·12:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-46880?
CVE-2021-46880 is a vulnerability in LibreSSL and OpenBSD that allows authentication bypass due to the discarding of errors for unverified certificate chains.
2
How severe is CVE-2021-46880?
CVE-2021-46880 has a severity rating of 9.8 (critical).
3
Which software is affected by CVE-2021-46880?
LibreSSL versions before 3.4.2 and OpenBSD versions before 7.0 errata 006 are affected by CVE-2021-46880.
4
How can I fix CVE-2021-46880?
To fix CVE-2021-46880, you should update to LibreSSL 3.4.2, or apply OpenBSD 7.0 errata 006.
5
Where can I find more information about CVE-2021-46880?
More information about CVE-2021-46880 can be found in the references: [link1], [link2], [link3].