CVE-2021-3449
published 2021-03-25CVE-2021-3449: An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the…
PriorityP349medium5.9CVSS 3.1
AVNACHPRNUINSUCNINAH
EPSS
62.91%
99.1th percentile
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer dereference will result, leading to a crash and a denial of service attack. A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which is the default configuration). OpenSSL TLS clients are not impacted by this issue. All OpenSSL 1.1.1 versions are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1k. OpenSSL 1.0.2 is not impacted by this issue. Fixed in OpenSSL 1.1.1k (Affected 1.1.1-1.1.1j).
Affected
107 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| checkpoint | multi-domain_management_firmware | — | — |
| checkpoint | multi-domain_management_firmware | — | — |
| checkpoint | quantum_security_gateway_firmware | — | — |
| checkpoint | quantum_security_gateway_firmware | — | — |
| checkpoint | quantum_security_management_firmware | — | — |
| checkpoint | quantum_security_management_firmware | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | openssl | < openssl 1.1.1k-1 (bookworm) | openssl 1.1.1k-1 (bookworm) |
| fedoraproject | fedora | — | — |
| freebsd | freebsd | — | — |
| mcafee | web_gateway | — | — |
| mcafee | web_gateway | — | — |
| mcafee | web_gateway | — | — |
| mcafee | web_gateway_cloud_service | — | — |
| mcafee | web_gateway_cloud_service | — | — |
| mcafee | web_gateway_cloud_service | — | — |
| msrc | microsoft_visual_studio_2017_version_15.9 | — | — |
| msrc | microsoft_visual_studio_2019_version_16.11 | — | — |
| msrc | microsoft_visual_studio_2019_version_16.4 | — | — |
| msrc | microsoft_visual_studio_2019_version_16.7 | — | — |
| msrc | microsoft_visual_studio_2019_version_16.9 | — | — |
| nodejs | node.js | 10.0.0 – 10.12.0 | — |
| nodejs | node.js | 10.13.0 – 10.24.0 | — |
| nodejs | node.js | 12.0.0 – 12.12.0 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Target TLS servers with TLSv1.2 and renegotiation enabled (default config). The attack requires sending a renegotiation ClientHello that omits the signature_algorithms extension (present in the initial ClientHello) but includes a signature_algorithms_cert extension, triggering a NULL pointer dereference crash. ↗
- →A server is only vulnerable if TLSv1.2 AND renegotiation are both enabled. Disabling either TLSv1.2 (TLSv1.3 is unaffected) or disabling renegotiation on the TLS server mitigates the issue. ↗
- →OpenSSL TLS clients are NOT impacted; detection/monitoring should focus exclusively on server-side TLS traffic for anomalous renegotiation handshakes. ↗
- ·Only OpenSSL versions 1.1.1 through 1.1.1j are affected. OpenSSL 1.0.2 is NOT impacted. The fix is present in OpenSSL 1.1.1k and later. ↗
- ·The vulnerability is exploitable only when both TLSv1.2 and renegotiation are enabled, which is the default OpenSSL server configuration — meaning most unpatched servers are exposed without any non-default configuration required. ↗
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.9MEDIUM
vendor_oracle7.5MEDIUM
vendor_cisco7.4HIGH
vendor_debian5.9MEDIUM
vendor_msrc5.9HIGH
vendor_redhat5.9MEDIUM
vendor_ubuntu5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2024-0014 Informational Bulletin: Impact of OSS CVEs in Cortex XDR Agent
vendor_paloalto·2024-11-07·CVSS 6.8
CVE-2014-0195 [MEDIUM] PAN-SA-2024-0014 Informational Bulletin: Impact of OSS CVEs in Cortex XDR Agent
PAN-SA-2024-0014 Informational Bulletin: Impact of OSS CVEs in Cortex XDR Agent
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to Cortex XDR Agent. While Cortex XDR Agent may include the
CVEs: CVE-2014-0195, CVE-2014-0224, CVE-2014-3509, CVE-2014-3512, CVE-2014-3513, CVE-2014-3567, CVE-2015-0209, CVE-2015-0292, CVE-2015-1789, CVE-2015-1791, CVE-2015-1793, CVE-2015-3194, CVE-2016-0705, CVE-2016-0797, CVE-2016-0798, CVE-2016-0799, CVE-2016-2105, CVE-2016-2106, CVE-2016-2108, CVE-2016-2109, CVE-2016-2176, CVE-2016-2177, CVE-2016-2179, CVE-2016-2180, CVE-2016-2181, CVE-2016-2182, CVE-2016-2183, CVE-2016-6302, CVE-2016-6303, CVE-2016-6304, CVE-2019-1551, CVE-2019-1552, CVE-2019-1559, CVE-2019-1563, CVE-2020-196
CISA ICS
Siemens OpenSSL Vulnerabilities in Industrial Products (Update B)
cisa_ics·2022-05-12
Siemens OpenSSL Vulnerabilities in Industrial Products (Update B)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens OpenSSL Vulnerabilities in Industrial Products (Update B)
Last RevisedAugust 11, 2022
Alert CodeICSA-22-104-05
## As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## 1. EXECUTIVE SUMMARY
- CVSS v3 5.9
- ATTENTION: Exploitable remotely/high attack complexity
- Vendor: Siemens
- Equipment: Siemens Industrial
CISA ICS
Siemens SINEC INS
cisa_ics·2022-03-10·CVSS 5.9
[MEDIUM] Siemens SINEC INS
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SINEC INS
Last RevisedMarch 10, 2022
Alert CodeICSA-22-069-09
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEC INS
- Vulnerability: Using Components with Known Vulnerabilities
## 2. RISK EVALUATION
Successful exploitation of this vulnerability in third-party components could allow an attacker to interfere with the affected product in various ways.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
Siemens reports this vulnerability affects the following SINEC INS (Infrastructure Netw
CISA ICS
Hitachi Energy APM Edge (Update A)
cisa_ics·2021-12-02·CVSS 9.1
[CRITICAL] Hitachi Energy APM Edge (Update A)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Hitachi Energy APM Edge (Update A)
Last RevisedOctober 18, 2022
Alert CodeICSA-21-336-06
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.2
- ATTENTION: Low attack complexity
- Vendor: Hitachi Energy
- Equipment: Transformer Asset Performance Management (APM) Edge
- Vulnerability: Reliance on Uncontrolled Component
## 2. UPDATE OR REPOSTED INFORMATION
This updated advisory is a follow-up to the original advisory titled “ICSA-21-336-06 Hitachi Energy APM Edge” that was published December 02, 2021, on the ICS webpage on cisa.gov/ics.
## 3. RISK EVALUATION
Successful exploitation of thi
Microsoft
OpenSSL: CVE-2021-3449 NULL pointer deref in signature_algorithms processing
vendor_msrc·2021-10-12·CVSS 5.9
CVE-2021-3449 [MEDIUM] OpenSSL: CVE-2021-3449 NULL pointer deref in signature_algorithms processing
OpenSSL: CVE-2021-3449 NULL pointer deref in signature_algorithms processing
FAQ: Why is this OpenSSL Software Foundation CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in OpenSSL Software which is consumed by Microsoft Visual Studio. It is being documented in the Security Update Guide to announce that the latest builds of Visual Studio are no longer vulnerable. Please see Security Update Guide Supports CVEs Assigned by Industry Partners for more information.
Visual Studio: Visual Studio
OpenSSL Software Foundation: OpenSSL Software Foundation
Impact: Denial of Service
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Remediation: Release Not
Ubuntu
PostgreSQL vulnerabilities
vendor_ubuntu·2021-08-12·CVSS 5.9
CVE-2021-3449 [MEDIUM] PostgreSQL vulnerabilities
Title: PostgreSQL vulnerabilities
Summary: Several security issues were fixed in PostgreSQL.
It was discovered that the PostgresQL planner could create incorrect plans
in certain circumstances. A remote attacker could use this issue to cause
PostgreSQL to crash, resulting in a denial of service, or possibly obtain
sensitive information from memory. This issue only affected Ubuntu 20.04
LTS and Ubuntu 21.04. (CVE-2021-3677)
It was discovered that PostgreSQL incorrectly handled certain SSL
renegotiation ClientHello messages from clients. A remote attacker could
possibly use this issue to cause PostgreSQL to crash, resulting in a denial
of service. (CVE-2021-3449)
Instructions: This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you
Oracle
Oracle Oracle MySQL Risk Matrix: Server: Packaging (OpenSSL) — CVE-2021-3449
vendor_oracle·2021-04-15·CVSS 7.5
CVE-2021-3449 [MEDIUM] Oracle Oracle MySQL Risk Matrix: Server: Packaging (OpenSSL) — CVE-2021-3449
Oracle Oracle MySQL Risk Matrix: Server: Packaging (OpenSSL) vulnerability
CVE: CVE-2021-3449
CVSS: 7.5
Protocol: MySQL Protocol
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2021 (APR 2021)
BSD
FreeBSD-SA-21:07.openssl: Multiple vulnerabilities in OpenSSL
bsd_advisories·2021-03-25·CVSS 5.9
CVE-2021-3449 [MEDIUM] FreeBSD-SA-21:07.openssl: Multiple vulnerabilities in OpenSSL
FreeBSD-SA-21:07.openssl Security Advisory
The FreeBSD Project
Topic: Multiple vulnerabilities in OpenSSL
Category: contrib
Module: openssl
Announced: 2021-03-25
Affects: FreeBSD 12.2 and later
Corrected: 2021-03-25 15:45:19 UTC (stable/13, 13.0-STABLE)
2021-03-25 16:25:06 UTC (releng/13.0, 13.0-RC3-p1)
2021-03-25 17:14:46 UTC (stable/12, 12.2-STABLE)
2021-03-25 23:45:45 UTC (releng/12.2, 12.2-RELEASE-p5)
CVE Name: CVE-2021-3449, CVE-2021-3450
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit .
I. Background
FreeBSD includes software from the OpenSSL Project. The OpenSSL Project is a
collaborative effort to develop a robust, commercial-grade, full-featured
Open Source t
Ubuntu
OpenSSL vulnerability
vendor_ubuntu·2021-03-25
CVE-2021-3449 OpenSSL vulnerability
Title: OpenSSL vulnerability
Summary: OpenSSL could be made to crash if it received specially
crafted network traffic.
It was discovered that OpenSSL incorrectly handled certain renegotiation
ClientHello messages. A remote attacker could use this issue to cause
OpenSSL to crash, resulting in a denial of service.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Cisco
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: March 2021
vendor_cisco·2021-03-25·CVSS 7.4
CVE-2021-3449 [HIGH] CWE-295 Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: March 2021
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: March 2021
On March 25, 2021, the OpenSSL Project released a security advisory, OpenSSL Security Advisory [25 March 2021], that disclosed two vulnerabilities.
Exploitation of these vulnerabilities could allow an attacker to use a valid non-certificate authority (CA) certificate to act as a CA and sign a certificate for an arbitrary organization, user or device, or to cause a denial of service (DoS) condition.
This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-openssl-2021-GHY28dJd
Red Hat
openssl: NULL pointer dereference in signature_algorithms processing
vendor_redhat·2021-03-25·CVSS 5.9
CVE-2021-3449 [MEDIUM] openssl: NULL pointer dereference in signature_algorithms processing
openssl: NULL pointer dereference in signature_algorithms processing
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer dereference will result, leading to a crash and a denial of service attack. A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which is the default configuration). OpenSSL TLS clients are not impacted by this issue. All OpenSSL 1.1.1 versions are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1k. OpenSSL 1.0.2 is not impacted by this issue. Fixed in OpenSSL 1.1.
Debian
CVE-2021-3449: openssl - An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation Clie...
vendor_debian·2021·CVSS 5.9
CVE-2021-3449 [MEDIUM] CVE-2021-3449: openssl - An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation Clie...
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer dereference will result, leading to a crash and a denial of service attack. A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which is the default configuration). OpenSSL TLS clients are not impacted by this issue. All OpenSSL 1.1.1 versions are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1k. OpenSSL 1.0.2 is not impacted by this issue. Fixed in OpenSSL 1.1.1k (Affected 1.1.1-1.1.1j).
Scope: local
bookworm: resolved (fixed in
Cisco
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: March 2021
vendor_cisco·CVSS 3.1
CVE-2021-3449 Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: March 2021
CVE-2021-3449: Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: March 2021
On March 25, 2021, the OpenSSL Project released a security advisory, OpenSSL Security Advisory [25 March 2021], that disclosed two vulnerabilities. Exploitation of these vulnerabilities could allow an attacker to use a valid non-certificate authority (CA) certificate to act as a CA and sign a certificate for an arbitrary organization, user or device, or to cause a denial of service (DoS) condition. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-openssl-2021-GHY28dJd
CVSS: 3.1
CWE: CWE-295, CWE-476, CWE-295, CWE-476
Bug IDs: CSCvx82619, CSCvx82617, CSCvx82705, CSCvx82705, CSCvx82740
OSV
openssl-src NULL pointer Dereference in signature_algorithms processing
osv·2021-08-25
CVE-2021-3449 [MEDIUM] openssl-src NULL pointer Dereference in signature_algorithms processing
openssl-src NULL pointer Dereference in signature_algorithms processing
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer dereference will result, leading to a crash and a denial of service attack. A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which is the default configuration). OpenSSL TLS clients are not impacted by this issue. All OpenSSL 1.1.1 versions are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1k. OpenSSL 1.0.2 is not impacted by this issue. Fixed in OpenSSL 1
GHSA
openssl-src NULL pointer Dereference in signature_algorithms processing
ghsa·2021-08-25
CVE-2021-3449 [MEDIUM] CWE-476 openssl-src NULL pointer Dereference in signature_algorithms processing
openssl-src NULL pointer Dereference in signature_algorithms processing
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer dereference will result, leading to a crash and a denial of service attack. A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which is the default configuration). OpenSSL TLS clients are not impacted by this issue. All OpenSSL 1.1.1 versions are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1k. OpenSSL 1.0.2 is not impacted by this issue. Fixed in OpenSSL 1
OSV
postgresql-10, postgresql-12, postgresql-13 vulnerabilities
osv·2021-08-12·CVSS 5.9
CVE-2021-3677 [MEDIUM] postgresql-10, postgresql-12, postgresql-13 vulnerabilities
postgresql-10, postgresql-12, postgresql-13 vulnerabilities
It was discovered that the PostgresQL planner could create incorrect plans
in certain circumstances. A remote attacker could use this issue to cause
PostgreSQL to crash, resulting in a denial of service, or possibly obtain
sensitive information from memory. This issue only affected Ubuntu 20.04
LTS and Ubuntu 21.04. (CVE-2021-3677)
It was discovered that PostgreSQL incorrectly handled certain SSL
renegotiation ClientHello messages from clients. A remote attacker could
possibly use this issue to cause PostgreSQL to crash, resulting in a denial
of service. (CVE-2021-3449)
OSV
NULL pointer deref in signature_algorithms processing
osv·2021-05-01
CVE-2021-3449 NULL pointer deref in signature_algorithms processing
NULL pointer deref in signature_algorithms processing
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation
ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits
the signature_algorithms extension (where it was present in the initial
ClientHello), but includes a signature_algorithms_cert extension then a NULL
pointer dereference will result, leading to a crash and a denial of service
attack.
A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which
is the default configuration). OpenSSL TLS clients are not impacted by this
issue.
OSV
CVE-2021-3449: An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client
osv·2021-03-25·CVSS 5.9
CVE-2021-3449 [MEDIUM] CVE-2021-3449: An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer dereference will result, leading to a crash and a denial of service attack. A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which is the default configuration). OpenSSL TLS clients are not impacted by this issue. All OpenSSL 1.1.1 versions are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1k. OpenSSL 1.0.2 is not impacted by this issue. Fixed in OpenSSL 1.1.1k (Affected 1.1.1-1.1.1j).
No detection rules found.
No public exploits indexed.
Trailofbits
Keeping the wolves out of wolfSSL
blogs_trailofbits·2023-01-12·CVSS 6.5
CVE-2022-38152 [MEDIUM] Keeping the wolves out of wolfSSL
Trail of Bits is publicly disclosing four vulnerabilities that affect wolfSSL: CVE-2022-38152, CVE-2022-38153, CVE-2022-39173, and CVE-2022-42905. The four issues, which have CVSS scores ranging from medium to critical, can all result in a denial of service (DoS). These vulnerabilities have been discovered automatically using the novel protocol fuzzer tlspuffin. This blog post will explore these vulnerabilities, then provide an in-depth overview of the fuzzer.
tlspuffin is a fuzzer inspired by formal protocol verification. Initially developed as part of my internship at LORIA, INRIA, France, it is especially targeted against cryptographic protocols like TLS or SSH.
During my internship at Trail of Bits, we pushed protocol fuzzing even further by supporting a new protocol (SSH), adding mo
Trailofbits
Keeping the wolves out of wolfSSL
blogs_trailofbits·2023-01-12·CVSS 6.5
CVE-2022-38152 [MEDIUM] Keeping the wolves out of wolfSSL
Trail of Bits is publicly disclosing four vulnerabilities that affect wolfSSL: CVE-2022-38152 , CVE-2022-38153 , CVE-2022-39173 , and CVE-2022-42905 . The four issues, which have CVSS scores ranging from medium to critical, can all result in a denial of service (DoS). These vulnerabilities have been discovered automatically using the novel protocol fuzzer tlspuffin . This blog post will explore these vulnerabilities, then provide an in-depth overview of the fuzzer.
tlspuffin is a fuzzer inspired by formal protocol verification. Initially developed as part of my internship at LORIA, INRIA, France , it is especially targeted against cryptographic protocols like TLS or SSH.
During my internship at Trail of Bits, we pushed protocol fuzzing even further by supporting a new protocol (SSH), add
Checkpoint
5th April – Threat Intelligence Report
blogs_checkpoint·2021-04-05
CVE-2021-21975 5th April – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 5th April – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 5th April, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Personal information of some 553 million Facebook users from 100 countries has been stolen and published online for free in a hacking forum. The records include full name, Facebook ID, phone number, email, location, bio and more.
Iranian APT group Charming Kitten, linked to the government, has launched a new phishing campaign
Bugzilla
CVE-2021-3449 openssl: NULL pointer dereference in signature_algorithms processing
bugzilla·2021-03-22·CVSS 5.9
CVE-2021-3449 [MEDIUM] CVE-2021-3449 openssl: NULL pointer dereference in signature_algorithms processing
CVE-2021-3449 openssl: NULL pointer dereference in signature_algorithms processing
As per upstream:
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial
ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer dereference will result, leading to a crash and a denial of service attack.
A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which is the default configuration). OpenSSL TLS clients are not impacted by this issue.
All OpenSSL 1.1.1 versions are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1k.
OpenSSL 1.0.2 is not impacted b
http://www.openwall.com/lists/oss-security/2021/03/27/1http://www.openwall.com/lists/oss-security/2021/03/27/2http://www.openwall.com/lists/oss-security/2021/03/28/3http://www.openwall.com/lists/oss-security/2021/03/28/4https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-772220.pdfhttps://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=fb9fa6b51defd48157eeb207f52181f735d96148https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44845https://kc.mcafee.com/corporate/index?page=content&id=SB10356https://lists.debian.org/debian-lts-announce/2021/08/msg00029.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CCBFLLVQVILIVGZMBJL3IXZGKWQISYNP/https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0013https://security.FreeBSD.org/advisories/FreeBSD-SA-21:07.openssl.aschttps://security.gentoo.org/glsa/202103-03https://security.netapp.com/advisory/ntap-20210326-0006/https://security.netapp.com/advisory/ntap-20210513-0002/https://security.netapp.com/advisory/ntap-20240621-0006/https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-openssl-2021-GHY28dJdhttps://www.debian.org/security/2021/dsa-4875https://www.openssl.org/news/secadv/20210325.txthttps://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://www.tenable.com/security/tns-2021-05https://www.tenable.com/security/tns-2021-06https://www.tenable.com/security/tns-2021-09https://www.tenable.com/security/tns-2021-10http://www.openwall.com/lists/oss-security/2021/03/27/1http://www.openwall.com/lists/oss-security/2021/03/27/2http://www.openwall.com/lists/oss-security/2021/03/28/3http://www.openwall.com/lists/oss-security/2021/03/28/4https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-772220.pdfhttps://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=fb9fa6b51defd48157eeb207f52181f735d96148https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44845https://kc.mcafee.com/corporate/index?page=content&id=SB10356https://lists.debian.org/debian-lts-announce/2021/08/msg00029.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CCBFLLVQVILIVGZMBJL3IXZGKWQISYNP/https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0013https://security.FreeBSD.org/advisories/FreeBSD-SA-21:07.openssl.aschttps://security.gentoo.org/glsa/202103-03https://security.netapp.com/advisory/ntap-20210326-0006/https://security.netapp.com/advisory/ntap-20210513-0002/https://security.netapp.com/advisory/ntap-20240621-0006/https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-openssl-2021-GHY28dJdhttps://www.debian.org/security/2021/dsa-4875https://www.openssl.org/news/secadv/20210325.txthttps://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://www.tenable.com/security/tns-2021-05https://www.tenable.com/security/tns-2021-06https://www.tenable.com/security/tns-2021-09https://www.tenable.com/security/tns-2021-10
2021-03-25
Published