CVE-2020-1968
published 2020-09-09CVE-2020-1968: The Raccoon attack exploits a flaw in the TLS specification which can lead to an attacker being able to compute the pre-master secret in connections which have…
PriorityP420low3.7CVSS 3.1
AVNACHPRNUINSUCLINAN
EPSS
4.80%
91.0th percentile
The Raccoon attack exploits a flaw in the TLS specification which can lead to an attacker being able to compute the pre-master secret in connections which have used a Diffie-Hellman (DH) based ciphersuite. In such a case this would result in the attacker being able to eavesdrop on all encrypted communications sent over that TLS connection. The attack can only be exploited if an implementation re-uses a DH secret across multiple TLS connections. Note that this issue only impacts DH ciphersuites and not ECDH ciphersuites. This issue affects OpenSSL 1.0.2 which is out of support and no longer receiving public updates. OpenSSL 1.1.1 is not vulnerable to this issue. Fixed in OpenSSL 1.0.2w (Affected 1.0.2-1.0.2v).
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | openssl | < openssl 1.1.0c-1 (bookworm) | openssl 1.1.0c-1 (bookworm) |
| fujitsu | m10-1_firmware | < xcp2400 | xcp2400 |
| fujitsu | m10-1_firmware | < xcp3100 | xcp3100 |
| fujitsu | m10-4_firmware | < xcp2400 | xcp2400 |
| fujitsu | m10-4_firmware | < xcp3100 | xcp3100 |
| fujitsu | m10-4s_firmware | < xcp2400 | xcp2400 |
| fujitsu | m10-4s_firmware | < xcp3100 | xcp3100 |
| fujitsu | m12-1_firmware | < xcp2400 | xcp2400 |
| fujitsu | m12-1_firmware | < xcp3100 | xcp3100 |
| fujitsu | m12-2_firmware | < xcp2400 | xcp2400 |
| fujitsu | m12-2_firmware | < xcp3100 | xcp3100 |
| fujitsu | m12-2s_firmware | < xcp2400 | xcp2400 |
| fujitsu | m12-2s_firmware | < xcp3100 | xcp3100 |
| openssl | openssl | — | — |
| openssl | openssl | >= 0 < 1.1.0c-1 | 1.1.0c-1 |
| openssl | openssl | >= 0 < 1.1.0c-1 | 1.1.0c-1 |
| openssl | openssl | >= 0 < 1.1.0c-1 | 1.1.0c-1 |
| openssl | openssl | >= 0 < 1.1.0c-1 | 1.1.0c-1 |
| openssl | openssl | >= 0 < 1.0.2g-1ubuntu4.17 | 1.0.2g-1ubuntu4.17 |
| openssl | openssl | >= 0 < 1.0.1f-1ubuntu2.27+esm10 | 1.0.1f-1ubuntu2.27+esm10 |
| openssl | openssl | 1.0.2 – 1.0.2v | — |
| oracle | ethernet_switch_es1-24_firmware | — | — |
CVSS provenance
nvdv3.13.7LOWCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv4.7MEDIUM
vendor_ubuntu4.7MEDIUM
vendor_debian3.7LOW
vendor_oracle3.7LOW
vendor_redhat3.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2024-0014 Informational Bulletin: Impact of OSS CVEs in Cortex XDR Agent
vendor_paloalto·2024-11-07·CVSS 6.8
CVE-2014-0195 [MEDIUM] PAN-SA-2024-0014 Informational Bulletin: Impact of OSS CVEs in Cortex XDR Agent
PAN-SA-2024-0014 Informational Bulletin: Impact of OSS CVEs in Cortex XDR Agent
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to Cortex XDR Agent. While Cortex XDR Agent may include the
CVEs: CVE-2014-0195, CVE-2014-0224, CVE-2014-3509, CVE-2014-3512, CVE-2014-3513, CVE-2014-3567, CVE-2015-0209, CVE-2015-0292, CVE-2015-1789, CVE-2015-1791, CVE-2015-1793, CVE-2015-3194, CVE-2016-0705, CVE-2016-0797, CVE-2016-0798, CVE-2016-0799, CVE-2016-2105, CVE-2016-2106, CVE-2016-2108, CVE-2016-2109, CVE-2016-2176, CVE-2016-2177, CVE-2016-2179, CVE-2016-2180, CVE-2016-2181, CVE-2016-2182, CVE-2016-2183, CVE-2016-6302, CVE-2016-6303, CVE-2016-6304, CVE-2019-1551, CVE-2019-1552, CVE-2019-1559, CVE-2019-1563, CVE-2020-196
Ubuntu
OpenSSL vulnerabilities
vendor_ubuntu·2024-09-18·CVSS 3.7
CVE-2024-0727 [LOW] OpenSSL vulnerabilities
Title: OpenSSL vulnerabilities
Summary: Several security issues were fixed in OpenSSL.
Robert Merget, Marcus Brinkmann, Nimrod Aviram, and Juraj Somorovsky
discovered that certain Diffie-Hellman ciphersuites in the TLS
specification and implemented by OpenSSL contained a flaw. A remote
attacker could possibly use this issue to eavesdrop on encrypted
communications. This was fixed in this update by removing the insecure
ciphersuites from OpenSSL. (CVE-2020-1968)
Paul Kehrer discovered that OpenSSL incorrectly handled certain input
lengths in EVP functions. A remote attacker could possibly use this issue
to cause OpenSSL to crash, resulting in a denial of service.
(CVE-2021-23840)
Elison Niven discovered that OpenSSL incorrectly handled the c_rehash
script. A local attacker could possibl
CISA ICS
Hitachi Energy FACTS Control Platform (FCP) Product
cisa_ics·2022-08-30·CVSS 3.7
[LOW] Hitachi Energy FACTS Control Platform (FCP) Product
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Hitachi Energy FACTS Control Platform (FCP) Product
Last RevisedAugust 30, 2022
Alert CodeICSA-22-242-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.5
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Hitachi Energy
- Equipment: FACTS Control Platform (FCP) Product
- Vulnerability: Inconsistent Interpretation of HTTP Requests, Use After Free, Classic Buffer Overflow, Integer Underflow, Improper Certificate Validation, Observable Discrepancy.
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities may allow an attacker to eavesdrop on the traffic betw
CISA ICS
Hitachi Energy Gateway Station (GWS) Product
cisa_ics·2022-08-30·CVSS 3.7
[LOW] Hitachi Energy Gateway Station (GWS) Product
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Hitachi Energy Gateway Station (GWS) Product
Last RevisedAugust 30, 2022
Alert CodeICSA-22-242-02
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.5
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Hitachi Energy
- Equipment: Gateway Station (GWS) Product
- Vulnerability: Inconsistent Interpretation of HTTP Requests, Use After Free, Classic Buffer Overflow, Integer Underflow, Improper Certificate Validation, Observable Discrepancy
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow unauthorized users to eavesdrop on the traffic between netwo
CISA ICS
Hitachi Energy System Data Manager
cisa_ics·2022-04-26·CVSS 7.5
[HIGH] Hitachi Energy System Data Manager
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Hitachi Energy System Data Manager
Last RevisedApril 26, 2022
Alert CodeICSA-22-116-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.5
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Hitachi Energy
- Equipment: System Data Manager – SDM600
- Vulnerabilities: Integer Overflow or Wraparound, Reachable Assertion, Type Confusion, Uncontrolled Recursion, Observable Discrepancy
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker to eavesdrop on traffic or to cause a denial-of-service condition.
## 3. TECHNICAL DETAILS
## 3.1 A
CISA ICS
Hitachi Energy MicroSCADA Pro/X SYS600
cisa_ics·2022-04-21
Hitachi Energy MicroSCADA Pro/X SYS600
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Hitachi Energy MicroSCADA Pro/X SYS600
Last RevisedApril 21, 2022
Alert CodeICSA-22-111-03
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Hitachi Energy
- Equipment: MicroSCADA Pro/X SYS600
- Vulnerabilities: Observable Discrepancy, HTTP Request Smuggling, Classic Buffer Overflow, Improper Certificate Validation, Improper Restriction of Operations within the Bounds of a Memory Buffer, Exposure of Sensitive Information to an Unauthorized Actor
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities coul
Oracle
Oracle Oracle Systems Risk Matrix: Firmware (OpenSSL) — CVE-2020-1968
vendor_oracle·2022-04-15·CVSS 3.7
CVE-2020-1968 [LOW] Oracle Oracle Systems Risk Matrix: Firmware (OpenSSL) — CVE-2020-1968
Oracle Oracle Systems Risk Matrix: Firmware (OpenSSL) vulnerability
CVE: CVE-2020-1968
CVSS: 3.7
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
CISA ICS
Hitachi Energy RTU500 series
cisa_ics·2021-12-02·CVSS 3.7
[LOW] Hitachi Energy RTU500 series
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Hitachi Energy RTU500 series
Last RevisedDecember 02, 2021
Alert CodeICSA-21-336-08
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.6
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Hitachi Energy
- Equipment: RTU500 series
- Vulnerabilities: Observable Discrepancy, Buffer Over-read, Out-of-bounds Read
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker to eavesdrop on traffic, retrieve information from memory, or cause a denial-of-service condition.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following versions
Oracle
Oracle Oracle Systems Risk Matrix: Firmware (OpenSSL) — CVE-2020-1968
vendor_oracle·2021-10-15·CVSS 3.7
CVE-2020-1968 [LOW] Oracle Oracle Systems Risk Matrix: Firmware (OpenSSL) — CVE-2020-1968
Oracle Oracle Systems Risk Matrix: Firmware (OpenSSL) vulnerability
CVE: CVE-2020-1968
CVSS: 3.7
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2021 (OCT 2021)
Palo Alto
PAN-OS: Impact of the Raccoon Attack Vulnerability CVE-2020-1968
vendor_paloalto·2021-10-13·CVSS 3.7
CVE-2020-1968 [LOW] CWE-203 PAN-OS: Impact of the Raccoon Attack Vulnerability CVE-2020-1968
PAN-OS: Impact of the Raccoon Attack Vulnerability CVE-2020-1968
In versions of Palo Alto Networks PAN-OS software earlier than PAN-OS 10.0, the DHE cipher available for use in traffic decryption improperly shares a cryptographic secret across multiple TLS connections, which weakens its cryptographic strength. This is a prerequisite for successful exploitation of the Raccoon attack (CVE-2020-1968), which allows an attacker to eavesdrop on encrypted traffic over those TLS connections.
Components that are known to be impacted by this vulnerability:
SSL Forward-Proxy
SSL Inbound Inspection
GlobalProtect Portal
GlobalProtect Gateway
GlobalProtect Clientless VPN
Affected products: PAN-OS, Prisma Access
Solution: Apply any of the workarounds to mitigate the risk of CVE-2020-1968.
This issue
Oracle
Oracle Oracle PeopleSoft Risk Matrix: Security (OpenSSL) — CVE-2020-1968
vendor_oracle·2021-01-15·CVSS 3.7
CVE-2020-1968 [LOW] Oracle Oracle PeopleSoft Risk Matrix: Security (OpenSSL) — CVE-2020-1968
Oracle Oracle PeopleSoft Risk Matrix: Security (OpenSSL) vulnerability
CVE: CVE-2020-1968
CVSS: 3.7
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2021 (JAN 2021)
Ubuntu
OpenSSL vulnerabilities
vendor_ubuntu·2020-09-16·CVSS 4.7
CVE-2019-1547 [MEDIUM] OpenSSL vulnerabilities
Title: OpenSSL vulnerabilities
Summary: Several security issues were fixed in OpenSSL.
Robert Merget, Marcus Brinkmann, Nimrod Aviram, and Juraj Somorovsky
discovered that certain Diffie-Hellman ciphersuites in the TLS
specification and implemented by OpenSSL contained a flaw. A remote
attacker could possibly use this issue to eavesdrop on encrypted
communications. This was fixed in this update by removing the insecure
ciphersuites from OpenSSL. (CVE-2020-1968)
Cesar Pereida García, Sohaib ul Hassan, Nicola Tuveri, Iaroslav Gridin,
Alejandro Cabrera Aldaya, and Billy Brumley discovered that OpenSSL
incorrectly handled ECDSA signatures. An attacker could possibly use this
issue to perform a timing side-channel attack and recover private ECDSA
keys. This issue only affected Ubuntu 18.04 L
Red Hat
openssl: Information exposure when DH secret are reused across multiple TLS connections
vendor_redhat·2020-09-09·CVSS 3.7
CVE-2020-1968 [LOW] CWE-385 openssl: Information exposure when DH secret are reused across multiple TLS connections
openssl: Information exposure when DH secret are reused across multiple TLS connections
The Raccoon attack exploits a flaw in the TLS specification which can lead to an attacker being able to compute the pre-master secret in connections which have used a Diffie-Hellman (DH) based ciphersuite. In such a case this would result in the attacker being able to eavesdrop on all encrypted communications sent over that TLS connection. The attack can only be exploited if an implementation re-uses a DH secret across multiple TLS connections. Note that this issue only impacts DH ciphersuites and not ECDH ciphersuites. This issue affects OpenSSL 1.0.2 which is out of support and no longer receiving public updates. OpenSSL 1.1.1 is not vulnerable to this issue. Fixed in OpenSSL 1.0.2w (Affected 1.0.2-1
Debian
CVE-2020-1968: openssl - The Raccoon attack exploits a flaw in the TLS specification which can lead to an...
vendor_debian·2020·CVSS 3.7
CVE-2020-1968 [LOW] CVE-2020-1968: openssl - The Raccoon attack exploits a flaw in the TLS specification which can lead to an...
The Raccoon attack exploits a flaw in the TLS specification which can lead to an attacker being able to compute the pre-master secret in connections which have used a Diffie-Hellman (DH) based ciphersuite. In such a case this would result in the attacker being able to eavesdrop on all encrypted communications sent over that TLS connection. The attack can only be exploited if an implementation re-uses a DH secret across multiple TLS connections. Note that this issue only impacts DH ciphersuites and not ECDH ciphersuites. This issue affects OpenSSL 1.0.2 which is out of support and no longer receiving public updates. OpenSSL 1.1.1 is not vulnerable to this issue. Fixed in OpenSSL 1.0.2w (Affected 1.0.2-1.0.2v).
Scope: local
bookworm: resolved (fixed in 1.1.0c-1)
bullseye: resolved (fixed in
OSV
openssl vulnerabilities
osv·2024-09-18·CVSS 3.7
CVE-2020-1968 [LOW] openssl vulnerabilities
openssl vulnerabilities
Robert Merget, Marcus Brinkmann, Nimrod Aviram, and Juraj Somorovsky
discovered that certain Diffie-Hellman ciphersuites in the TLS
specification and implemented by OpenSSL contained a flaw. A remote
attacker could possibly use this issue to eavesdrop on encrypted
communications. This was fixed in this update by removing the insecure
ciphersuites from OpenSSL. (CVE-2020-1968)
Paul Kehrer discovered that OpenSSL incorrectly handled certain input
lengths in EVP functions. A remote attacker could possibly use this issue
to cause OpenSSL to crash, resulting in a denial of service.
(CVE-2021-23840)
Elison Niven discovered that OpenSSL incorrectly handled the c_rehash
script. A local attacker could possibly use this issue to execute arbitrary
commands when c_rehash is
GHSA
GHSA-mh8f-5gw2-5wgh: The Raccoon attack exploits a flaw in the TLS specification which can lead to an attacker being able to compute the pre-master secret in connections w
ghsa_unreviewed·2022-05-24
CVE-2020-1968 [MEDIUM] CWE-203 GHSA-mh8f-5gw2-5wgh: The Raccoon attack exploits a flaw in the TLS specification which can lead to an attacker being able to compute the pre-master secret in connections w
The Raccoon attack exploits a flaw in the TLS specification which can lead to an attacker being able to compute the pre-master secret in connections which have used a Diffie-Hellman (DH) based ciphersuite. In such a case this would result in the attacker being able to eavesdrop on all encrypted communications sent over that TLS connection. The attack can only be exploited if an implementation re-uses a DH secret across multiple TLS connections. Note that this issue only impacts DH ciphersuites and not ECDH ciphersuites. This issue affects OpenSSL 1.0.2 which is out of support and no longer receiving public updates. OpenSSL 1.1.1 is not vulnerable to this issue. Fixed in OpenSSL 1.0.2w (Affected 1.0.2-1.0.2v).
OSV
openssl, openssl1.0 vulnerabilities
osv·2020-09-16·CVSS 4.7
CVE-2020-1968 [MEDIUM] openssl, openssl1.0 vulnerabilities
openssl, openssl1.0 vulnerabilities
Robert Merget, Marcus Brinkmann, Nimrod Aviram, and Juraj Somorovsky
discovered that certain Diffie-Hellman ciphersuites in the TLS
specification and implemented by OpenSSL contained a flaw. A remote
attacker could possibly use this issue to eavesdrop on encrypted
communications. This was fixed in this update by removing the insecure
ciphersuites from OpenSSL. (CVE-2020-1968)
Cesar Pereida García, Sohaib ul Hassan, Nicola Tuveri, Iaroslav Gridin,
Alejandro Cabrera Aldaya, and Billy Brumley discovered that OpenSSL
incorrectly handled ECDSA signatures. An attacker could possibly use this
issue to perform a timing side-channel attack and recover private ECDSA
keys. This issue only affected Ubuntu 18.04 LTS. (CVE-2019-1547)
Guido Vranken discovered that O
OSV
CVE-2020-1968: The Raccoon attack exploits a flaw in the TLS specification which can lead to an attacker being able to compute the pre-master secret in connections w
osv·2020-09-09·CVSS 3.7
CVE-2020-1968 [LOW] CVE-2020-1968: The Raccoon attack exploits a flaw in the TLS specification which can lead to an attacker being able to compute the pre-master secret in connections w
The Raccoon attack exploits a flaw in the TLS specification which can lead to an attacker being able to compute the pre-master secret in connections which have used a Diffie-Hellman (DH) based ciphersuite. In such a case this would result in the attacker being able to eavesdrop on all encrypted communications sent over that TLS connection. The attack can only be exploited if an implementation re-uses a DH secret across multiple TLS connections. Note that this issue only impacts DH ciphersuites and not ECDH ciphersuites. This issue affects OpenSSL 1.0.2 which is out of support and no longer receiving public updates. OpenSSL 1.1.1 is not vulnerable to this issue. Fixed in OpenSSL 1.0.2w (Affected 1.0.2-1.0.2v).
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-1968 openssl11: openssl: Information exposure when DH secret are reused across multiple TLS connections [epel-7]
bugzilla·2020-09-09·CVSS 3.7
CVE-2020-1968 [LOW] CVE-2020-1968 openssl11: openssl: Information exposure when DH secret are reused across multiple TLS connections [epel-7]
CVE-2020-1968 openssl11: openssl: Information exposure when DH secret are reused across multiple TLS connections [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Bugzilla
CVE-2020-1968 openssl: Information exposure when DH secret are reused across multiple TLS connections
bugzilla·2020-09-09·CVSS 3.7
CVE-2020-1968 [LOW] CVE-2020-1968 openssl: Information exposure when DH secret are reused across multiple TLS connections
CVE-2020-1968 openssl: Information exposure when DH secret are reused across multiple TLS connections
The Raccoon attack exploits a flaw in the TLS specification which can lead to an attacker being able to compute the pre-master secret in connections which have used a Diffie-Hellman (DH) based ciphersuite. In such a case this would result in the attacker being able to eavesdrop on all encrypted communications sent over that TLS connection. The attack can only be exploited if an implementation re-uses a DH secret across multiple TLS connections. Note that this issue only impacts DH ciphersuites and not ECDH ciphersuites. This issue affects OpenSSL 1.0.2 which is out of support and no longer receiving public updates. OpenSSL 1.1.1 is not vulnerable to this issue. Fixed in OpenSSL 1.0.2w (Af
Bugzilla
CVE-2020-1968 openssl: Information exposure when DH secret are reused across multiple TLS connections [fedora-all]
bugzilla·2020-09-09·CVSS 3.7
CVE-2020-1968 [LOW] CVE-2020-1968 openssl: Information exposure when DH secret are reused across multiple TLS connections [fedora-all]
CVE-2020-1968 openssl: Information exposure when DH secret are reused across multiple TLS connections [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issu
https://lists.debian.org/debian-lts-announce/2020/09/msg00016.htmlhttps://security.gentoo.org/glsa/202210-02https://security.netapp.com/advisory/ntap-20200911-0004/https://usn.ubuntu.com/4504-1/https://www.openssl.org/news/secadv/20200909.txthttps://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://lists.debian.org/debian-lts-announce/2020/09/msg00016.htmlhttps://security.gentoo.org/glsa/202210-02https://security.netapp.com/advisory/ntap-20200911-0004/https://usn.ubuntu.com/4504-1/https://www.openssl.org/news/secadv/20200909.txthttps://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.html
2020-09-09
Published