Lucene search

K
ubuntucveUbuntu.comUB:CVE-2021-3449
HistoryMar 25, 2021 - 12:00 a.m.

CVE-2021-3449

2021-03-2500:00:00
ubuntu.com
ubuntu.com
26

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

5.9 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

0.005 Low

EPSS

Percentile

76.4%

An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation
ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello
omits the signature_algorithms extension (where it was present in the
initial ClientHello), but includes a signature_algorithms_cert extension
then a NULL pointer dereference will result, leading to a crash and a
denial of service attack. A server is only vulnerable if it has TLSv1.2 and
renegotiation enabled (which is the default configuration). OpenSSL TLS
clients are not impacted by this issue. All OpenSSL 1.1.1 versions are
affected by this issue. Users of these versions should upgrade to OpenSSL
1.1.1k. OpenSSL 1.0.2 is not impacted by this issue. Fixed in OpenSSL
1.1.1k (Affected 1.1.1-1.1.1j).

Notes

Author Note
mdeslaur does not affect 1.0.2 edk2 doesn’t implement a server, so not vulnerable to this issue
OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchopenssl< 1.1.1-1ubuntu2.1~18.04.9UNKNOWN
ubuntu20.04noarchopenssl< 1.1.1f-1ubuntu2.3UNKNOWN
ubuntu20.10noarchopenssl< 1.1.1f-1ubuntu4.3UNKNOWN
ubuntu21.04noarchopenssl< 1.1.1j-1ubuntu3UNKNOWN
ubuntu21.10noarchopenssl< 1.1.1j-1ubuntu3UNKNOWN
ubuntu22.04noarchopenssl< 1.1.1j-1ubuntu3UNKNOWN
ubuntu22.10noarchopenssl< 1.1.1j-1ubuntu3UNKNOWN
ubuntu23.04noarchopenssl< 1.1.1j-1ubuntu3UNKNOWN
ubuntu23.10noarchopenssl< 1.1.1j-1ubuntu3UNKNOWN
ubuntu24.04noarchopenssl< 1.1.1j-1ubuntu3UNKNOWN
Rows per page:
1-10 of 151

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

5.9 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

0.005 Low

EPSS

Percentile

76.4%