USN-4662-1: OpenSSL vulnerability
Published Dec 8, 2020
·Updated
David Benjamin discovered that OpenSSL incorrectly handled comparing certificates containing a EDIPartyName name type. A remote attacker could possibly use this issue to cause OpenSSL to crash, resulting in a denial of service.
Affected Software
10 affected componentsFixes available
All of the following
ubuntu/libssl1.1<1.1.1f-1ubuntu4.1
1.1.1f-1ubuntu4.1
Ubuntu Ubuntu=20.10
All of the following
ubuntu/libssl1.1<1.1.1f-1ubuntu2.1
1.1.1f-1ubuntu2.1
Ubuntu Ubuntu=20.04
All of the following
ubuntu/libssl1.0.0<1.0.2n-1ubuntu5.5
1.0.2n-1ubuntu5.5
Ubuntu Ubuntu=18.04
All of the following
ubuntu/libssl1.1<1.1.1-1ubuntu2.1~18.04.7
1.1.1-1ubuntu2.1~18.04.7
Ubuntu Ubuntu=18.04
All of the following
ubuntu/libssl1.0.0<1.0.2g-1ubuntu4.18
1.0.2g-1ubuntu4.18
Ubuntu Ubuntu=16.04
Event History
Dec 8, 2020
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-4662-1?
The USN-4662-1 vulnerability has a severity rating that suggests it could lead to a denial of service if exploited.
2
How do I fix USN-4662-1?
To fix USN-4662-1, update OpenSSL to the recommended version for your specific Ubuntu release.
3
What specific versions of Ubuntu are affected by USN-4662-1?
USN-4662-1 affects Ubuntu versions 16.04, 18.04, 20.04, and 20.10.
4
Can USN-4662-1 allow remote code execution?
No, USN-4662-1 does not allow remote code execution; it primarily leads to a denial of service.
5
How can I identify if my system is vulnerable to USN-4662-1?
You can identify if your system is vulnerable to USN-4662-1 by checking the version of the libssl package installed on your Ubuntu system.