Lucene search

K
osvGoogleOSV:USN-4745-1
HistoryFeb 23, 2021 - 7:33 p.m.

openssl vulnerabilities

2021-02-2319:33:18
Google
osv.dev
3

6.7 Medium

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

74.4%

David Benjamin discovered that OpenSSL incorrectly handled comparing
certificates containing a EDIPartyName name type. A remote attacker could
possibly use this issue to cause OpenSSL to crash, resulting in a denial of
service. (CVE-2020-1971)

Tavis Ormandy discovered that OpenSSL incorrectly handled parsing issuer
fields. A remote attacker could possibly use this issue to cause OpenSSL to
crash, resulting in a denial of service. (CVE-2021-23841)