CVE-2021-3450
published 2021-03-25CVE-2021-3450: The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is not set by default. Starting from…
PriorityP357high7.4CVSS 3.1
AVNACHPRNUINSUCHIHAN
EPSS
18.34%
96.9th percentile
The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is not set by default. Starting from OpenSSL version 1.1.1h a check to disallow certificates in the chain that have explicitly encoded elliptic curve parameters was added as an additional strict check. An error in the implementation of this check meant that the result of a previous check to confirm that certificates in the chain are valid CA certificates was overwritten. This effectively bypasses the check that non-CA certificates must not be able to issue other certificates. If a "purpose" has been configured then there is a subsequent opportunity for checks that the certificate is a valid CA. All of the named "purpose" values implemented in libcrypto perform this check. Therefore, where a purpose is set the certificate chain will still be rejected even when the strict flag has been used. A purpose is set by default in libssl client and server certificate verification routines, but it can be overridden or removed by an application. In order to be affected, an application must explicitly set the X509_V_FLAG_X509_STRICT verification flag and either not set a purpose for the certificate verification or, in the case of TLS client or server applications, override the default purpose. OpenSSL versions 1.1.1h and newer are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1k. OpenSSL 1.0.2 is not impacted by this issue. Fixed in OpenSSL 1.1.1k (Affected 1.1.1h-1.1.1j).
Affected
57 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openssl | < openssl 1.1.1k-1 (bookworm) | openssl 1.1.1k-1 (bookworm) |
| fedoraproject | fedora | — | — |
| freebsd | freebsd | — | — |
| mcafee | web_gateway | — | — |
| mcafee | web_gateway | — | — |
| mcafee | web_gateway | — | — |
| mcafee | web_gateway_cloud_service | — | — |
| mcafee | web_gateway_cloud_service | — | — |
| mcafee | web_gateway_cloud_service | — | — |
| msrc | microsoft_visual_studio_2017_version_15.9 | — | — |
| msrc | microsoft_visual_studio_2019_version_16.11 | — | — |
| msrc | microsoft_visual_studio_2019_version_16.4 | — | — |
| msrc | microsoft_visual_studio_2019_version_16.7 | — | — |
| msrc | microsoft_visual_studio_2019_version_16.9 | — | — |
| nodejs | node.js | >= 10.0.0 < 10.24.1 | 10.24.1 |
| nodejs | node.js | >= 12.0.0 < 12.22.1 | 12.22.1 |
| nodejs | node.js | >= 14.0.0 < 14.16.1 | 14.16.1 |
| nodejs | node.js | >= 15.0.0 < 15.14.0 | 15.14.0 |
| openssl | openssl | — | — |
| openssl | openssl | >= 0 < 1.1.1k-1 | 1.1.1k-1 |
| openssl | openssl | >= 0 < 1.1.1k-1 | 1.1.1k-1 |
| openssl | openssl | >= 0 < 1.1.1k-1 | 1.1.1k-1 |
| openssl | openssl | >= 0 < 1.1.1k-1 | 1.1.1k-1 |
| openssl | openssl | >= 1.1.1h < 1.1.1k | 1.1.1k |
| oracle | commerce_guided_search | — | — |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv7.4HIGH
vendor_cisco7.4HIGH
vendor_debian7.4HIGH
vendor_msrc7.4HIGH
vendor_oracle7.4HIGH
vendor_redhat7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2024-0014 Informational Bulletin: Impact of OSS CVEs in Cortex XDR Agent
vendor_paloalto·2024-11-07·CVSS 6.8
CVE-2014-0195 [MEDIUM] PAN-SA-2024-0014 Informational Bulletin: Impact of OSS CVEs in Cortex XDR Agent
PAN-SA-2024-0014 Informational Bulletin: Impact of OSS CVEs in Cortex XDR Agent
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to Cortex XDR Agent. While Cortex XDR Agent may include the
CVEs: CVE-2014-0195, CVE-2014-0224, CVE-2014-3509, CVE-2014-3512, CVE-2014-3513, CVE-2014-3567, CVE-2015-0209, CVE-2015-0292, CVE-2015-1789, CVE-2015-1791, CVE-2015-1793, CVE-2015-3194, CVE-2016-0705, CVE-2016-0797, CVE-2016-0798, CVE-2016-0799, CVE-2016-2105, CVE-2016-2106, CVE-2016-2108, CVE-2016-2109, CVE-2016-2176, CVE-2016-2177, CVE-2016-2179, CVE-2016-2180, CVE-2016-2181, CVE-2016-2182, CVE-2016-2183, CVE-2016-6302, CVE-2016-6303, CVE-2016-6304, CVE-2019-1551, CVE-2019-1552, CVE-2019-1559, CVE-2019-1563, CVE-2020-196
Palo Alto
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-02-14·CVSS 9.8
CVE-2017-18342 [CRITICAL] PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2017-18342, CVE-2017-8923, CVE-2017-9120, CVE-2019-1551, CVE-2019-16865, CVE-2019-16905, CVE-2019-19523, CVE-2019-19528, CVE-2019-19911, CVE-2020-0404, CVE-2020-0431, CVE-2020-0466, CVE-2020-10379, CVE-2020-11538, CVE-2020-11608, CVE-2020-12114, CVE-2020-12321, CVE-2020-12362, CVE-2020-12363, CVE-2020-12364, CVE-2020-13757, CVE-2020-14314, CVE-2020-14351, CVE-2020-15778, CVE-2020-1967, CVE-2020-24394, CVE-2020-24504, CVE-2020-25211, CVE-2020-25212, CVE-2020-25284, CVE-2020-25285, CVE-2020-25717, CVE-2020-26541, CVE-2020-2715
Oracle
Oracle Oracle Commerce Risk Matrix: Framework, Experience Manager (OpenSSL) — CVE-2021-3450
vendor_oracle·2022-07-15·CVSS 7.4
CVE-2021-3450 [HIGH] Oracle Oracle Commerce Risk Matrix: Framework, Experience Manager (OpenSSL) — CVE-2021-3450
Oracle Oracle Commerce Risk Matrix: Framework, Experience Manager (OpenSSL) vulnerability
CVE: CVE-2021-3450
CVSS: 7.4
Protocol: TLS
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2022 (JUL 2022)
Oracle
Oracle Oracle Enterprise Manager Risk Matrix: Privilege Management (OpenSSL) — CVE-2021-3450
vendor_oracle·2022-04-15·CVSS 7.4
CVE-2021-3450 [HIGH] Oracle Oracle Enterprise Manager Risk Matrix: Privilege Management (OpenSSL) — CVE-2021-3450
Oracle Oracle Enterprise Manager Risk Matrix: Privilege Management (OpenSSL) vulnerability
CVE: CVE-2021-3450
CVSS: 7.4
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
CISA ICS
Siemens SINEC INS
cisa_ics·2022-03-10·CVSS 5.9
[MEDIUM] Siemens SINEC INS
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SINEC INS
Last RevisedMarch 10, 2022
Alert CodeICSA-22-069-09
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEC INS
- Vulnerability: Using Components with Known Vulnerabilities
## 2. RISK EVALUATION
Successful exploitation of this vulnerability in third-party components could allow an attacker to interfere with the affected product in various ways.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
Siemens reports this vulnerability affects the following SINEC INS (Infrastructure Netw
Oracle
Oracle Oracle Secure Backup Risk Matrix: Oracle Secure Backup (OpenSSL) — CVE-2021-3450
vendor_oracle·2021-10-15·CVSS 7.4
CVE-2021-3450 [HIGH] Oracle Oracle Secure Backup Risk Matrix: Oracle Secure Backup (OpenSSL) — CVE-2021-3450
Oracle Oracle Secure Backup Risk Matrix: Oracle Secure Backup (OpenSSL) vulnerability
CVE: CVE-2021-3450
CVSS: 7.4
Protocol: TLS
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2021 (OCT 2021)
Microsoft
OpenSSL: CVE-2021-3450 CA certificate check bypass with X509_V_FLAG_X509_STRICT
vendor_msrc·2021-10-12·CVSS 7.4
CVE-2021-3450 [HIGH] OpenSSL: CVE-2021-3450 CA certificate check bypass with X509_V_FLAG_X509_STRICT
OpenSSL: CVE-2021-3450 CA certificate check bypass with X509_V_FLAG_X509_STRICT
FAQ: Why is this OpenSSL Software Foundation CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in OpenSSL Software which is consumed by Microsoft Visual Studio. It is being documented in the Security Update Guide to announce that the latest builds of Visual Studio are no longer vulnerable. Please see Security Update Guide Supports CVEs Assigned by Industry Partners for more information.
Visual Studio: Visual Studio
OpenSSL Software Foundation: OpenSSL Software Foundation
Impact: Information Disclosure
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Unlikely;Older Software Release:Exploitation Unlikely;DOS:N/A
Remediation: Release N
Oracle
Oracle Oracle MySQL Risk Matrix: Connector/C++ (OpenSSL) — CVE-2021-3450
vendor_oracle·2021-07-15·CVSS 7.4
CVE-2021-3450 [HIGH] Oracle Oracle MySQL Risk Matrix: Connector/C++ (OpenSSL) — CVE-2021-3450
Oracle Oracle MySQL Risk Matrix: Connector/C++ (OpenSSL) vulnerability
CVE: CVE-2021-3450
CVSS: 7.4
Protocol: MySQL Protocol
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2021 (JUL 2021)
Oracle
Oracle Oracle Java SE Risk Matrix: Node (Node.js) — CVE-2021-3450
vendor_oracle·2021-04-15·CVSS 7.4
CVE-2021-3450 [HIGH] Oracle Oracle Java SE Risk Matrix: Node (Node.js) — CVE-2021-3450
Oracle Oracle Java SE Risk Matrix: Node (Node.js) vulnerability
CVE: CVE-2021-3450
CVSS: 7.4
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2021 (APR 2021)
BSD
FreeBSD-SA-21:07.openssl: Multiple vulnerabilities in OpenSSL
bsd_advisories·2021-03-25·CVSS 5.9
CVE-2021-3449 [MEDIUM] FreeBSD-SA-21:07.openssl: Multiple vulnerabilities in OpenSSL
FreeBSD-SA-21:07.openssl Security Advisory
The FreeBSD Project
Topic: Multiple vulnerabilities in OpenSSL
Category: contrib
Module: openssl
Announced: 2021-03-25
Affects: FreeBSD 12.2 and later
Corrected: 2021-03-25 15:45:19 UTC (stable/13, 13.0-STABLE)
2021-03-25 16:25:06 UTC (releng/13.0, 13.0-RC3-p1)
2021-03-25 17:14:46 UTC (stable/12, 12.2-STABLE)
2021-03-25 23:45:45 UTC (releng/12.2, 12.2-RELEASE-p5)
CVE Name: CVE-2021-3449, CVE-2021-3450
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit .
I. Background
FreeBSD includes software from the OpenSSL Project. The OpenSSL Project is a
collaborative effort to develop a robust, commercial-grade, full-featured
Open Source t
Cisco
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: March 2021
vendor_cisco·2021-03-25·CVSS 7.4
CVE-2021-3449 [HIGH] CWE-295 Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: March 2021
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: March 2021
On March 25, 2021, the OpenSSL Project released a security advisory, OpenSSL Security Advisory [25 March 2021], that disclosed two vulnerabilities.
Exploitation of these vulnerabilities could allow an attacker to use a valid non-certificate authority (CA) certificate to act as a CA and sign a certificate for an arbitrary organization, user or device, or to cause a denial of service (DoS) condition.
This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-openssl-2021-GHY28dJd
Red Hat
openssl: CA certificate check bypass with X509_V_FLAG_X509_STRICT
vendor_redhat·2021-03-25·CVSS 7.4
CVE-2021-3450 [HIGH] CWE-295 openssl: CA certificate check bypass with X509_V_FLAG_X509_STRICT
openssl: CA certificate check bypass with X509_V_FLAG_X509_STRICT
The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is not set by default. Starting from OpenSSL version 1.1.1h a check to disallow certificates in the chain that have explicitly encoded elliptic curve parameters was added as an additional strict check. An error in the implementation of this check meant that the result of a previous check to confirm that certificates in the chain are valid CA certificates was overwritten. This effectively bypasses the check that non-CA certificates must not be able to issue other certificates. If a "purpose" has been configured then there is a subsequent opportunity for checks that the certificate is a valid CA. All of t
Debian
CVE-2021-3450: openssl - The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certi...
vendor_debian·2021·CVSS 7.4
CVE-2021-3450 [HIGH] CVE-2021-3450: openssl - The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certi...
The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is not set by default. Starting from OpenSSL version 1.1.1h a check to disallow certificates in the chain that have explicitly encoded elliptic curve parameters was added as an additional strict check. An error in the implementation of this check meant that the result of a previous check to confirm that certificates in the chain are valid CA certificates was overwritten. This effectively bypasses the check that non-CA certificates must not be able to issue other certificates. If a "purpose" has been configured then there is a subsequent opportunity for checks that the certificate is a valid CA. All of the named "purpose" values implemented in libcrypto perform this che
Cisco
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: March 2021
vendor_cisco·CVSS 3.1
CVE-2021-3450 Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: March 2021
CVE-2021-3450: Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: March 2021
On March 25, 2021, the OpenSSL Project released a security advisory, OpenSSL Security Advisory [25 March 2021], that disclosed two vulnerabilities. Exploitation of these vulnerabilities could allow an attacker to use a valid non-certificate authority (CA) certificate to act as a CA and sign a certificate for an arbitrary organization, user or device, or to cause a denial of service (DoS) condition. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-openssl-2021-GHY28dJd
CVSS: 3.1
CWE: CWE-295, CWE-476, CWE-295, CWE-476
Bug IDs: CSCvx82619, CSCvx82617, CSCvx82705, CSCvx82705, CSCvx82740
OSV
Certificate check bypass in openssl-src
osv·2021-08-25
CVE-2021-3450 [HIGH] Certificate check bypass in openssl-src
Certificate check bypass in openssl-src
The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is not set by default. Starting from OpenSSL version 1.1.1h a check to disallow certificates in the chain that have explicitly encoded elliptic curve parameters was added as an additional strict check. An error in the implementation of this check meant that the result of a previous check to confirm that certificates in the chain are valid CA certificates was overwritten. This effectively bypasses the check that non-CA certificates must not be able to issue other certificates. If a "purpose" has been configured then there is a subsequent opportunity for checks that the certificate is a valid CA. All of the named "purpose" values
GHSA
Certificate check bypass in openssl-src
ghsa·2021-08-25
CVE-2021-3450 [HIGH] CWE-295 Certificate check bypass in openssl-src
Certificate check bypass in openssl-src
The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is not set by default. Starting from OpenSSL version 1.1.1h a check to disallow certificates in the chain that have explicitly encoded elliptic curve parameters was added as an additional strict check. An error in the implementation of this check meant that the result of a previous check to confirm that certificates in the chain are valid CA certificates was overwritten. This effectively bypasses the check that non-CA certificates must not be able to issue other certificates. If a "purpose" has been configured then there is a subsequent opportunity for checks that the certificate is a valid CA. All of the named "purpose" values
OSV
CA certificate check bypass with X509_V_FLAG_X509_STRICT
osv·2021-05-01
CVE-2021-3450 CA certificate check bypass with X509_V_FLAG_X509_STRICT
CA certificate check bypass with X509_V_FLAG_X509_STRICT
The X509_V_FLAG_X509_STRICT flag enables additional security checks of the
certificates present in a certificate chain. It is not set by default.
Starting from OpenSSL version 1.1.1h a check to disallow certificates in
the chain that have explicitly encoded elliptic curve parameters was added
as an additional strict check.
An error in the implementation of this check meant that the result of a
previous check to confirm that certificates in the chain are valid CA
certificates was overwritten. This effectively bypasses the check
that non-CA certificates must not be able to issue other certificates.
If a "purpose" has been configured then there is a subsequent opportunity
for checks that the certificate is a valid CA. All of the nam
OSV
CVE-2021-3450: The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain
osv·2021-03-25·CVSS 7.4
CVE-2021-3450 [HIGH] CVE-2021-3450: The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain
The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is not set by default. Starting from OpenSSL version 1.1.1h a check to disallow certificates in the chain that have explicitly encoded elliptic curve parameters was added as an additional strict check. An error in the implementation of this check meant that the result of a previous check to confirm that certificates in the chain are valid CA certificates was overwritten. This effectively bypasses the check that non-CA certificates must not be able to issue other certificates. If a "purpose" has been configured then there is a subsequent opportunity for checks that the certificate is a valid CA. All of the named "purpose" values implemented in libcrypto perform this che
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2021-3450 openssl: CA certificate check bypass with X509_V_FLAG_X509_STRICT
bugzilla·2021-03-22·CVSS 7.4
CVE-2021-3450 [HIGH] CVE-2021-3450 openssl: CA certificate check bypass with X509_V_FLAG_X509_STRICT
CVE-2021-3450 openssl: CA certificate check bypass with X509_V_FLAG_X509_STRICT
As per upstream:
The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is not set by default.
Starting from OpenSSL version 1.1.1h a check to disallow certificates withexplicitly encoded elliptic curve parameters in the chain was added to the strict checks.
An error in the implementation of this check meant that the result of a previous check to confirm that certificates in the chain are valid CA certificates was overwritten. This effectively bypasses the check that non-CA certificates must not be able to issue other certificates.
If a "purpose" has been configured then a subsequent check that the certificate is consistent with that purpo
Trailofbits
We build X.509 chains so you don’t have to
blogs_trailofbits·2024-01-25
We build X.509 chains so you don’t have to
For the past eight months, Trail of Bits has worked with the Python Cryptographic Authority to build cryptography-x509-verification, a brand-new, pure-Rust implementation of the X.509 path validation algorithm that TLS and other encryption and authentication protocols are built on. Our implementation is fast, standards-conforming, and memory-safe, giving the Python ecosystem a modern alternative to OpenSSL’s misuse- and vulnerability-prone X.509 APIs for HTTPS certificate verification, among other protocols. This is a foundational security improvement that will benefit every Python network programmer and, consequently, the internet as a whole.
Our implementation has been exposed as a Python API and is included in Cryptography’s 42.0.0 release series, meaning that Python developers can tak
Trailofbits
We build X.509 chains so you don’t have to
blogs_trailofbits·2024-01-25
We build X.509 chains so you don’t have to
For the past eight months, Trail of Bits has worked with the Python Cryptographic Authority to build cryptography-x509-verification , a brand-new, pure-Rust implementation of the X.509 path validation algorithm that TLS and other encryption and authentication protocols are built on. Our implementation is fast, standards-conforming, and memory-safe, giving the Python ecosystem a modern alternative to OpenSSL’s misuse- and vulnerability-prone X.509 APIs for HTTPS certificate verification, among other protocols. This is a foundational security improvement that will benefit every Python network programmer and, consequently, the internet as a whole.
Our implementation has been exposed as a Python API and is included in Cryptography’s 42.0.0 release series , meaning that Python developers can t
Checkpoint
5th April – Threat Intelligence Report
blogs_checkpoint·2021-04-05
CVE-2021-21975 5th April – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 5th April – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 5th April, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Personal information of some 553 million Facebook users from 100 countries has been stolen and published online for free in a hacking forum. The records include full name, Facebook ID, phone number, email, location, bio and more.
Iranian APT group Charming Kitten, linked to the government, has launched a new phishing campaign
http://www.openwall.com/lists/oss-security/2021/03/27/1http://www.openwall.com/lists/oss-security/2021/03/27/2http://www.openwall.com/lists/oss-security/2021/03/28/3http://www.openwall.com/lists/oss-security/2021/03/28/4https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdfhttps://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=2a40b7bc7b94dd7de897a74571e7024f0cf0d63bhttps://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44845https://kc.mcafee.com/corporate/index?page=content&id=SB10356https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CCBFLLVQVILIVGZMBJL3IXZGKWQISYNP/https://mta.openssl.org/pipermail/openssl-announce/2021-March/000198.htmlhttps://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0013https://security.FreeBSD.org/advisories/FreeBSD-SA-21:07.openssl.aschttps://security.gentoo.org/glsa/202103-03https://security.netapp.com/advisory/ntap-20210326-0006/https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-openssl-2021-GHY28dJdhttps://www.openssl.org/news/secadv/20210325.txthttps://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://www.tenable.com/security/tns-2021-05https://www.tenable.com/security/tns-2021-08https://www.tenable.com/security/tns-2021-09http://www.openwall.com/lists/oss-security/2021/03/27/1http://www.openwall.com/lists/oss-security/2021/03/27/2http://www.openwall.com/lists/oss-security/2021/03/28/3http://www.openwall.com/lists/oss-security/2021/03/28/4https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdfhttps://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=2a40b7bc7b94dd7de897a74571e7024f0cf0d63bhttps://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44845https://kc.mcafee.com/corporate/index?page=content&id=SB10356https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CCBFLLVQVILIVGZMBJL3IXZGKWQISYNP/https://mta.openssl.org/pipermail/openssl-announce/2021-March/000198.htmlhttps://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0013https://security.FreeBSD.org/advisories/FreeBSD-SA-21:07.openssl.aschttps://security.gentoo.org/glsa/202103-03https://security.netapp.com/advisory/ntap-20210326-0006/https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-openssl-2021-GHY28dJdhttps://www.openssl.org/news/secadv/20210325.txthttps://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://www.tenable.com/security/tns-2021-05https://www.tenable.com/security/tns-2021-08https://www.tenable.com/security/tns-2021-09
2021-03-25
Published