High
Canonical Ubuntu
David Benjamin discovered that OpenSSL incorrectly handled comparing certificates containing a EDIPartyName name type. A remote attacker could possibly use this issue to cause OpenSSL to crash, resulting in a denial of service.
CVEs contained in this USN include: CVE-2020-1971.
Severity is high unless otherwise noted.
Users of affected products are strongly encouraged to follow the mitigations below. The Cloud Foundry project recommends upgrading the following releases:
2021-01-13: Initial vulnerability report published.
CPE | Name | Operator | Version |
---|---|---|---|
cflinuxfs3 | lt | 0.212.0 | |
xenial stemcells | lt | 315.203 | |
xenial stemcells | lt | 456.130 | |
xenial stemcells | lt | 621.94 | |
cf deployment | lt | 15.4.0 |