CVE-2020-1971
published 2020-12-08CVE-2020-1971: The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a…
PriorityP335medium5.9CVSS 3.1
AVNACHPRNUINSUCNINAH
EPSS
6.97%
93.4th percentile
The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrectly when both GENERAL_NAMEs contain an EDIPARTYNAME. A NULL pointer dereference and a crash may occur leading to a possible denial of service attack. OpenSSL itself uses the GENERAL_NAME_cmp function for two purposes: 1) Comparing CRL distribution point names between an available CRL and a CRL distribution point embedded in an X509 certificate 2) When verifying that a timestamp response token signer matches the timestamp authority name (exposed via the API functions TS_RESP_verify_response and TS_RESP_verify_token) If an attacker can control both items being compared then that attacker could trigger a crash. For example if the attacker can trick a client or server into checking a malicious certificate against a malicious CRL then this may occur. Note that some applications automatically download CRLs based on a URL embedded in a certificate. This checking happens prior to the signatures on the certificate and CRL being verified. OpenSSL's s_server, s_client and verify tools have support for the "-crl_download" option which implements automatic CRL downloading and this attack has been demonstrated to work against those tools. Note that an unrelated bug means that affected versions of OpenSSL cannot parse or construct correct encodings of EDIPARTYNAME. However it is possible to construct a malformed EDIPARTYNAME that OpenSSL's parser will accept and hence trigger this attack. All OpenSSL 1.1.1 and 1.0.2 versions are affected by this issue. Other OpenSSL releases are out of support and have not been checked. Fixed in OpenSSL 1.1.1i (Affected 1.1.1-1.1.1h). Fixed in OpenSSL 1.0.2x (Affected 1.0.2-1.0.2w).
Affected
83 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | openssl | < openssl 1.1.1i-1 (bookworm) | openssl 1.1.1i-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | microsoft_visual_studio_2017_version_15.9 | — | — |
| msrc | microsoft_visual_studio_2019_version_16.11 | — | — |
| msrc | microsoft_visual_studio_2019_version_16.4 | — | — |
| msrc | microsoft_visual_studio_2019_version_16.7 | — | — |
| msrc | microsoft_visual_studio_2019_version_16.9 | — | — |
| netapp | e-series_santricity_os_controller | 11.0.0 – 11.60.3 | — |
| nodejs | node.js | 10.0.0 – 10.12.0 | — |
| nodejs | node.js | >= 10.13.0 < 10.23.1 | 10.23.1 |
| nodejs | node.js | 12.0.0 – 12.12.0 | — |
| nodejs | node.js | >= 12.13.0 < 12.20.1 | 12.20.1 |
| nodejs | node.js | 14.0.0 – 14.14.0 | — |
| nodejs | node.js | >= 14.15.0 < 14.15.4 | 14.15.4 |
| nodejs | node.js | >= 15.0.0 < 15.5.0 | 15.5.0 |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | >= 0 < 1.1.1i-1 | 1.1.1i-1 |
| openssl | openssl | >= 0 < 1.1.1i-1 | 1.1.1i-1 |
| openssl | openssl | >= 0 < 1.1.1i-1 | 1.1.1i-1 |
| openssl | openssl | >= 0 < 1.1.1i-1 | 1.1.1i-1 |
| openssl | openssl | >= 0 < 1.0.1f-1ubuntu2.27+esm2 | 1.0.1f-1ubuntu2.27+esm2 |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.9MEDIUM
vendor_oracle7.5MEDIUM
vendor_debian5.9MEDIUM
vendor_msrc5.9HIGH
vendor_redhat5.9MEDIUM
vendor_ubuntu5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2024-0014 Informational Bulletin: Impact of OSS CVEs in Cortex XDR Agent
vendor_paloalto·2024-11-07·CVSS 6.8
CVE-2014-0195 [MEDIUM] PAN-SA-2024-0014 Informational Bulletin: Impact of OSS CVEs in Cortex XDR Agent
PAN-SA-2024-0014 Informational Bulletin: Impact of OSS CVEs in Cortex XDR Agent
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to Cortex XDR Agent. While Cortex XDR Agent may include the
CVEs: CVE-2014-0195, CVE-2014-0224, CVE-2014-3509, CVE-2014-3512, CVE-2014-3513, CVE-2014-3567, CVE-2015-0209, CVE-2015-0292, CVE-2015-1789, CVE-2015-1791, CVE-2015-1793, CVE-2015-3194, CVE-2016-0705, CVE-2016-0797, CVE-2016-0798, CVE-2016-0799, CVE-2016-2105, CVE-2016-2106, CVE-2016-2108, CVE-2016-2109, CVE-2016-2176, CVE-2016-2177, CVE-2016-2179, CVE-2016-2180, CVE-2016-2181, CVE-2016-2182, CVE-2016-2183, CVE-2016-6302, CVE-2016-6303, CVE-2016-6304, CVE-2019-1551, CVE-2019-1552, CVE-2019-1559, CVE-2019-1563, CVE-2020-196
CISA ICS
Siemens SIDIS Prime
cisa_ics·2024-02-15·CVSS 7.4
[HIGH] Siemens SIDIS Prime
ICS Advisory
##
Siemens SIDIS Prime
Release DateFebruary 15, 2024
Alert CodeICSA-24-046-02
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 9.1
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIDIS Prime
- Vulnerabilities: Use of Insufficiently Random Values, NULL Pointer Dereference, Infinite Loop
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an unauthenticated attacker with
Oracle
Oracle Oracle Communications Risk Matrix: OC-CNE (OpenSSL) — CVE-2020-1971
vendor_oracle·2022-04-15·CVSS 5.9
CVE-2020-1971 [MEDIUM] Oracle Oracle Communications Risk Matrix: OC-CNE (OpenSSL) — CVE-2020-1971
Oracle Oracle Communications Risk Matrix: OC-CNE (OpenSSL) vulnerability
CVE: CVE-2020-1971
CVSS: 5.9
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
CISA ICS
Siemens SINEC INS
cisa_ics·2022-03-10·CVSS 5.9
[MEDIUM] Siemens SINEC INS
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SINEC INS
Last RevisedMarch 10, 2022
Alert CodeICSA-22-069-09
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEC INS
- Vulnerability: Using Components with Known Vulnerabilities
## 2. RISK EVALUATION
Successful exploitation of this vulnerability in third-party components could allow an attacker to interfere with the affected product in various ways.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
Siemens reports this vulnerability affects the following SINEC INS (Infrastructure Netw
CISA ICS
Hitachi Energy APM Edge (Update A)
cisa_ics·2021-12-02·CVSS 9.1
[CRITICAL] Hitachi Energy APM Edge (Update A)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Hitachi Energy APM Edge (Update A)
Last RevisedOctober 18, 2022
Alert CodeICSA-21-336-06
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.2
- ATTENTION: Low attack complexity
- Vendor: Hitachi Energy
- Equipment: Transformer Asset Performance Management (APM) Edge
- Vulnerability: Reliance on Uncontrolled Component
## 2. UPDATE OR REPOSTED INFORMATION
This updated advisory is a follow-up to the original advisory titled “ICSA-21-336-06 Hitachi Energy APM Edge” that was published December 02, 2021, on the ICS webpage on cisa.gov/ics.
## 3. RISK EVALUATION
Successful exploitation of thi
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: SSL Module (OpenSSL) — CVE-2020-1971
vendor_oracle·2021-10-15·CVSS 5.9
CVE-2020-1971 [MEDIUM] Oracle Oracle Fusion Middleware Risk Matrix: SSL Module (OpenSSL) — CVE-2020-1971
Oracle Oracle Fusion Middleware Risk Matrix: SSL Module (OpenSSL) vulnerability
CVE: CVE-2020-1971
CVSS: 5.9
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2021 (OCT 2021)
Microsoft
OpenSSL: CVE-2020-1971 EDIPARTYNAME NULL pointer de-reference
vendor_msrc·2021-10-12·CVSS 5.9
CVE-2020-1971 [MEDIUM] OpenSSL: CVE-2020-1971 EDIPARTYNAME NULL pointer de-reference
OpenSSL: CVE-2020-1971 EDIPARTYNAME NULL pointer de-reference
FAQ: Why is this OpenSSL Software Foundation CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in OpenSSL Software which is consumed by Microsoft Visual Studio. It is being documented in the Security Update Guide to announce that the latest builds of Visual Studio are no longer vulnerable. Please see Security Update Guide Supports CVEs Assigned by Industry Partners for more information.
Visual Studio: Visual Studio
OpenSSL Software Foundation: OpenSSL Software Foundation
Impact: Denial of Service
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Remediation: Release Notes
Reference:
Oracle
Oracle Oracle Enterprise Manager Risk Matrix: Discovery Framework (OpenSSL) — CVE-2020-1971
vendor_oracle·2021-07-15·CVSS 7.5
CVE-2020-1971 [MEDIUM] Oracle Oracle Enterprise Manager Risk Matrix: Discovery Framework (OpenSSL) — CVE-2020-1971
Oracle Oracle Enterprise Manager Risk Matrix: Discovery Framework (OpenSSL) vulnerability
CVE: CVE-2020-1971
CVSS: 7.5
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2021 (JUL 2021)
Oracle
Oracle Oracle Communications Risk Matrix: Routing (OpenSSL) — CVE-2020-1971
vendor_oracle·2021-04-15·CVSS 7.5
CVE-2020-1971 [MEDIUM] Oracle Oracle Communications Risk Matrix: Routing (OpenSSL) — CVE-2020-1971
Oracle Oracle Communications Risk Matrix: Routing (OpenSSL) vulnerability
CVE: CVE-2020-1971
CVSS: 7.5
Protocol: TLS
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2021 (APR 2021)
Ubuntu
OpenSSL vulnerabilities
vendor_ubuntu·2021-02-23·CVSS 5.9
CVE-2021-23841 [MEDIUM] OpenSSL vulnerabilities
Title: OpenSSL vulnerabilities
Summary: Several security issues were fixed in OpenSSL.
David Benjamin discovered that OpenSSL incorrectly handled comparing
certificates containing a EDIPartyName name type. A remote attacker could
possibly use this issue to cause OpenSSL to crash, resulting in a denial of
service. (CVE-2020-1971)
Tavis Ormandy discovered that OpenSSL incorrectly handled parsing issuer
fields. A remote attacker could possibly use this issue to cause OpenSSL to
crash, resulting in a denial of service. (CVE-2021-23841)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Oracle
Oracle Oracle MySQL Risk Matrix: MySQL Workbench (OpenSSL) — CVE-2020-1971
vendor_oracle·2021-01-15·CVSS 5.9
CVE-2020-1971 [MEDIUM] Oracle Oracle MySQL Risk Matrix: MySQL Workbench (OpenSSL) — CVE-2020-1971
Oracle Oracle MySQL Risk Matrix: MySQL Workbench (OpenSSL) vulnerability
CVE: CVE-2020-1971
CVSS: 5.9
Protocol: MySQL Workbench
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2021 (JAN 2021)
Palo Alto
PAN-SA-2020-0011 Informational: Impact of OpenSSL vulnerability CVE-2020-1971
vendor_paloalto·2020-12-09·CVSS 5.9
CVE-2020-1971 [MEDIUM] PAN-SA-2020-0011 Informational: Impact of OpenSSL vulnerability CVE-2020-1971
PAN-SA-2020-0011 Informational: Impact of OpenSSL vulnerability CVE-2020-1971
Palo Alto Networks Product Security Assurance team has evaluated the vulnerability CVE-2020-1971 that affects the OpenSSL library. The vulnerability does not have a security impact on PAN-OS, GlobalProtect App, or Cortex XSOAR. The scenarios required for successful
CVEs: CVE-2020-1971
Affected products: Cortex XSOAR, GlobalProtect, PAN-OS
BSD
FreeBSD-SA-20:33.openssl: OpenSSL NULL pointer de-reference
bsd_advisories·2020-12-08·CVSS 5.9
CVE-2020-1971 [MEDIUM] FreeBSD-SA-20:33.openssl: OpenSSL NULL pointer de-reference
FreeBSD-SA-20:33.openssl Security Advisory
The FreeBSD Project
Topic: OpenSSL NULL pointer de-reference
Category: contrib
Module: openssl
Announced: 2020-12-08
Affects: All supported versions of FreeBSD.
Corrected: 2020-12-08 18:28:49 UTC (stable/12, 12.2-STABLE)
2020-12-08 19:10:40 UTC (releng/12.2, 12.2-RELEASE-p2)
2020-12-08 19:10:40 UTC (releng/12.1, 12.1-RELEASE-p12)
2020-12-10 23:43:29 UTC (stable/11, 11.4-STABLE)
2020-12-14 21:20:55 UTC (releng/11.4, 11.4-RELEASE-p6)
CVE Name: CVE-2020-1971
Note: The OpenSSL project has published publicly available patches for
versions included in FreeBSD 12.x. FreeBSD 11.x includes an older OpenSSL
version, and patches for that version from from the OpenSSL project are
only available to premium support contract holders. This advisory includes
an
Ubuntu
OpenSSL vulnerability
vendor_ubuntu·2020-12-08
CVE-2020-1971 OpenSSL vulnerability
Title: OpenSSL vulnerability
Summary: OpenSSL could be made to crash if it processed specially crafted input.
David Benjamin discovered that OpenSSL incorrectly handled comparing
certificates containing a EDIPartyName name type. A remote attacker could
possibly use this issue to cause OpenSSL to crash, resulting in a denial of
service.
Instructions: After a standard system update you need to reboot your computer to make all
the necessary changes.
Red Hat
openssl: EDIPARTYNAME NULL pointer de-reference
vendor_redhat·2020-12-08·CVSS 5.9
CVE-2020-1971 [MEDIUM] CWE-476 openssl: EDIPARTYNAME NULL pointer de-reference
openssl: EDIPARTYNAME NULL pointer de-reference
The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrectly when both GENERAL_NAMEs contain an EDIPARTYNAME. A NULL pointer dereference and a crash may occur leading to a possible denial of service attack. OpenSSL itself uses the GENERAL_NAME_cmp function for two purposes: 1) Comparing CRL distribution point names between an available CRL and a CRL distribution point embedded in an X509 certificate 2) When verifying that a timestamp response token signer matches the timestamp authority name (exposed via
Debian
CVE-2020-1971: openssl - The X.509 GeneralName type is a generic type for representing different types of...
vendor_debian·2020·CVSS 5.9
CVE-2020-1971 [MEDIUM] CVE-2020-1971: openssl - The X.509 GeneralName type is a generic type for representing different types of...
The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrectly when both GENERAL_NAMEs contain an EDIPARTYNAME. A NULL pointer dereference and a crash may occur leading to a possible denial of service attack. OpenSSL itself uses the GENERAL_NAME_cmp function for two purposes: 1) Comparing CRL distribution point names between an available CRL and a CRL distribution point embedded in an X509 certificate 2) When verifying that a timestamp response token signer matches the timestamp authority name (exposed via the API functions TS_RESP_verify_response and TS
Palo Alto
Palo Alto Networks Security Advisories
vendor_paloalto·CVSS 5.9
CVE-2020-1971 [MEDIUM] Palo Alto Networks Security Advisories
Palo Alto Networks Security Advisories
CVEs: CVE-2020-1971
Affected products: Cortex Data, Cortex XDR, Cortex XSIAM, Cortex XSOAR, Cortex Xpanse, GlobalProtect, PAN-OS, Panorama, Prisma Access, Prisma Browser, Prisma Cloud, Prisma SD
GHSA
GHSA-whf2-mq76-2fhv: The X
ghsa_unreviewed·2022-05-24
CVE-2020-1971 [HIGH] CWE-476 GHSA-whf2-mq76-2fhv: The X
The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrectly when both GENERAL_NAMEs contain an EDIPARTYNAME. A NULL pointer dereference and a crash may occur leading to a possible denial of service attack. OpenSSL itself uses the GENERAL_NAME_cmp function for two purposes: 1) Comparing CRL distribution point names between an available CRL and a CRL distribution point embedded in an X509 certificate 2) When verifying that a timestamp response token signer matches the timestamp authority name (exposed via the API functions TS_RESP_verify_response and TS
OSV
CVE-2020-1971: In GENERAL_NAME_cmp of v3_genn
osv·2021-06-01
CVE-2020-1971 CVE-2020-1971: In GENERAL_NAME_cmp of v3_genn
In GENERAL_NAME_cmp of v3_genn.c , there is a possible denial of service due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
OSV
openssl vulnerabilities
osv·2021-02-23·CVSS 5.9
CVE-2020-1971 [MEDIUM] openssl vulnerabilities
openssl vulnerabilities
David Benjamin discovered that OpenSSL incorrectly handled comparing
certificates containing a EDIPartyName name type. A remote attacker could
possibly use this issue to cause OpenSSL to crash, resulting in a denial of
service. (CVE-2020-1971)
Tavis Ormandy discovered that OpenSSL incorrectly handled parsing issuer
fields. A remote attacker could possibly use this issue to cause OpenSSL to
crash, resulting in a denial of service. (CVE-2021-23841)
OSV
CVE-2020-1971: The X
osv·2020-12-08·CVSS 5.9
CVE-2020-1971 [MEDIUM] CVE-2020-1971: The X
The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrectly when both GENERAL_NAMEs contain an EDIPARTYNAME. A NULL pointer dereference and a crash may occur leading to a possible denial of service attack. OpenSSL itself uses the GENERAL_NAME_cmp function for two purposes: 1) Comparing CRL distribution point names between an available CRL and a CRL distribution point embedded in an X509 certificate 2) When verifying that a timestamp response token signer matches the timestamp authority name (exposed via the API functions TS_RESP_verify_response and TS
No detection rules found.
No public exploits indexed.
arXiv
Dissecting contact tracing apps in the Android platform
arxiv_fulltext·2021-05-21
Dissecting contact tracing apps in the Android platform
Dissecting contact tracing apps in the Android platform
[1]Vasileios Kouliaridis
[2]Georgios Kambourakis
[1]Efstratios Chatzoglou
[3]Dimitrios Geneiatakis
[4]Hua Wang
[1]Department of Information & Communication Systems Engineering, University of the Aegean, Greece
[2]European Commission, Joint Research Centre (JRC), 21027 Ispra (VA), Italy
[3]European Commission, Directorate-General for Informatics, 1000 Bruxelles/Brussel, Belgium
[4]Institute of Sustainable Industries and Liveable Cities, Victoria University, Melbourne, VIC 8001, Australia
This work is published in PLOS ONE, DOI: https://doi.org/10.1371/journal.pone.0251867.
Abstract: Contact tracing has historically been used to retard the spread of infectious diseases, but if it is exercised by hand in large-scale, it is known to b
Bugzilla
CVE-2020-1971 openssl: EDIPARTYNAME NULL pointer de-reference
bugzilla·2020-12-02·CVSS 5.9
CVE-2020-1971 [MEDIUM] CVE-2020-1971 openssl: EDIPARTYNAME NULL pointer de-reference
CVE-2020-1971 openssl: EDIPARTYNAME NULL pointer de-reference
As per upstream advisory:
The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME
to see if they are equal or not. This function behaves incorrectly when both GENERAL_NAMEs contain an EDIPARTYNAME. A NULL pointer dereference and a crash may occur leading to a possible denial of service attack.
OpenSSL itself uses the GENERAL_NAME_cmp function for two purposes:
1. Comparing CRL distribution point names between an available CRL and a CRL distribution point embedded in an X509 certificate
2. When verifying that a timestamp response token signer matche
Checkpoint
14th December – Threat Intelligence Bulletin
blogs_checkpoint·2020-12-14
CVE-2020-1971 14th December – Threat Intelligence Bulletin
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 14th December – Threat Intelligence Bulletin
For the latest discoveries in cyber research for the week of 14th December, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
The US Treasury Department and US Department of Commerce were victims of a cyberattack compromising their internal email traffic. Perhaps related , SolarWinds IT management software has been exploited in a supply chain attack, adding malicious code to its software updates released between March and June 2020.
Habana
http://www.openwall.com/lists/oss-security/2021/09/14/2https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdfhttps://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=2154ab83e14ede338d2ede9bbe5cdfce5d5a6c9ehttps://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=f960d81215ebf3f65e03d4d5d857fb9b666d6920https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44676https://lists.apache.org/thread.html/r63c6f2dd363d9b514d0a4bcf624580616a679898cc14c109a49b750c%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/rbb769f771711fb274e0a4acb1b5911c8aab544a6ac5e8c12d40c5143%40%3Ccommits.pulsar.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2020/12/msg00020.htmlhttps://lists.debian.org/debian-lts-announce/2020/12/msg00021.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DGSI34Y5LQ5RYXN4M2I5ZQT65LFVDOUU/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PWPSSZNZOBJU2YR6Z4TGHXKYW3YP5QG7/https://security.FreeBSD.org/advisories/FreeBSD-SA-20:33.openssl.aschttps://security.gentoo.org/glsa/202012-13https://security.netapp.com/advisory/ntap-20201218-0005/https://security.netapp.com/advisory/ntap-20210513-0002/https://security.netapp.com/advisory/ntap-20240621-0006/https://www.debian.org/security/2020/dsa-4807https://www.openssl.org/news/secadv/20201208.txthttps://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://www.tenable.com/security/tns-2020-11https://www.tenable.com/security/tns-2021-09https://www.tenable.com/security/tns-2021-10http://www.openwall.com/lists/oss-security/2021/09/14/2https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdfhttps://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=2154ab83e14ede338d2ede9bbe5cdfce5d5a6c9ehttps://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=f960d81215ebf3f65e03d4d5d857fb9b666d6920https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44676https://lists.apache.org/thread.html/r63c6f2dd363d9b514d0a4bcf624580616a679898cc14c109a49b750c%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/rbb769f771711fb274e0a4acb1b5911c8aab544a6ac5e8c12d40c5143%40%3Ccommits.pulsar.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2020/12/msg00020.htmlhttps://lists.debian.org/debian-lts-announce/2020/12/msg00021.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DGSI34Y5LQ5RYXN4M2I5ZQT65LFVDOUU/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PWPSSZNZOBJU2YR6Z4TGHXKYW3YP5QG7/https://security.FreeBSD.org/advisories/FreeBSD-SA-20:33.openssl.aschttps://security.gentoo.org/glsa/202012-13https://security.netapp.com/advisory/ntap-20201218-0005/https://security.netapp.com/advisory/ntap-20210513-0002/https://security.netapp.com/advisory/ntap-20240621-0006/https://www.debian.org/security/2020/dsa-4807https://www.openssl.org/news/secadv/20201208.txthttps://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://www.tenable.com/security/tns-2020-11https://www.tenable.com/security/tns-2021-09https://www.tenable.com/security/tns-2021-10
2020-12-08
Published