First published: Tue Feb 23 2021(Updated: )
David Benjamin discovered that OpenSSL incorrectly handled comparing certificates containing a EDIPartyName name type. A remote attacker could possibly use this issue to cause OpenSSL to crash, resulting in a denial of service. (CVE-2020-1971) Tavis Ormandy discovered that OpenSSL incorrectly handled parsing issuer fields. A remote attacker could possibly use this issue to cause OpenSSL to crash, resulting in a denial of service. (CVE-2021-23841)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libssl1.0.0 | <1.0.1f-1ubuntu2.27+esm2 | 1.0.1f-1ubuntu2.27+esm2 |
Ubuntu Ubuntu | =14.04 | |
All of | ||
ubuntu/libssl1.0.0 | <1.0.1-4ubuntu5.45 | 1.0.1-4ubuntu5.45 |
Ubuntu Ubuntu | =12.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.