[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250053

 
 

909

 
 

195940

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2-2021-1714 --- openssl11

ID: oval:org.secpod.oval:def:1700724Date: (C)2021-10-11   (M)2023-11-13
Class: PATCHFamily: unix




It was found that openssl assumed ASN.1 strings to be NUL terminated. A malicious actor may be able to force an application into calling openssl function with a specially crafted, non-NUL terminated string to deliberately hit this bug, which may result in a crash of the application, causing a Denial of Service attack, or possibly, memory disclosure. The highest threat from this vulnerability is to data confidentiality and system availability

Platform:
Amazon Linux 2
Product:
openssl11
Reference:
ALAS2-2021-1714
CVE-2021-3712
CVE    1
CVE-2021-3712
CPE    3
cpe:/a:openssl:openssl
cpe:/o:amazon:linux:2
cpe:/a:openssl:openssl:1.1

© SecPod Technologies