CVE-2021-3712
Severity
7.4HIGH
EPSS
0.4%
top 38.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 24
Latest updateNov 26
Description
ASN.1 strings are represented internally within OpenSSL as an ASN1_STRING structure which contains a buffer holding the string data and a field holding the buffer length. This contrasts with normal C strings which are repesented as a buffer for the string data which is terminated with a NUL (0) byte. Although not a strict requirement, ASN.1 strings that are parsed using OpenSSL's own "d2i" functions (and other similar parsing functions) as well as any string whose value has been set with the ASN…
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:HExploitability: 2.2 | Impact: 5.2
Affected Packages29 packages
Also affects: Debian Linux 10.0, 11.0, 9.0
Patches
🔴Vulnerability Details
10📋Vendor Advisories
15Oracle▶
Oracle Oracle Siebel CRM Risk Matrix: Siebel Core - Server Infrastructure (OpenSSL) — CVE-2021-3712↗2023-04-15
Oracle
▶