CVE Feed

    Dashboard / CVE / CVE-2021-3711

    CVE-2021-3711

    In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this function twice. The first time, on entry, the "out" parameter can be NULL and, on exit, the "outlen" parameter is populated with the buffer size required to hold the decrypted plaintext. The application can then allocate a sufficiently sized buffer and call EVP_PKEY_decrypt() again, but this time passing a non-NULL value for the "out" parameter. A bug in the implementation of the SM2 decryption code means that the calculation of the buffer size required to hold the plaintext returned by the first call to EVP_PKEY_decrypt() can be smaller than the actual size required by the second call. This can lead to a buffer overflow when EVP_PKEY_decrypt() is called by the application a second time with a buffer that is too small. A malicious attacker who is able present SM2 content for decryption to an application could cause attacker chosen data to overflow the buffer by up to a maximum of 62 bytes altering the contents of other data held after the buffer, possibly changing application behaviour or causing the application to crash. The location of the buffer is application dependent but is typically heap allocated. Fixed in OpenSSL 1.1.1l (Affected 1.1.1-1.1.1k).

    Published:Aug 24, 2021
    Last Modified:Nov 21, 2024
    EPS:Aug 24, 2021
    EPSS Score:0.02747
    CVSS Score:9.8

    Affected Products

    Vendor
    Debian
    Product
    Debian Linux
    Vendor
    Netapp
    Product
    Active Iq Unified Manager
    Vendor
    Netapp
    Product
    Clustered Data Ontap
    Vendor
    Netapp
    Product
    Clustered Data Ontap Antivirus Connector
    Vendor
    Netapp
    Product
    E-series Santricity Os Controller
    Vendor
    Netapp
    Product
    Hci Management Node
    Vendor
    Netapp
    Product
    Manageability Software Development Kit
    Vendor
    Netapp
    Product
    Oncommand Insight
    Vendor
    Netapp
    Product
    Oncommand Workflow Automation
    Vendor
    Netapp
    Product
    Santricity Smi-s Provider
    Vendor
    Netapp
    Product
    Snapcenter
    Vendor
    Netapp
    Product
    Solidfire
    Vendor
    Netapp
    Product
    Storage Encryption
    Vendor
    Openssl
    Product
    Openssl
    Vendor
    Oracle
    Product
    Communications Cloud Native Core Security Edge Protection Proxy
    Vendor
    Oracle
    Product
    Communications Cloud Native Core Unified Data Repository
    Vendor
    Oracle
    Product
    Communications Session Border Controller
    Vendor
    Oracle
    Product
    Communications Unified Session Manager
    Vendor
    Oracle
    Product
    Enterprise Communications Broker
    Vendor
    Oracle
    Product
    Enterprise Session Border Controller
    Vendor
    Oracle
    Product
    Essbase
    Vendor
    Oracle
    Product
    Health Sciences Inform Publisher
    Vendor
    Oracle
    Product
    Jd Edwards Enterpriseone Tools
    Vendor
    Oracle
    Product
    Jd Edwards World Security
    Vendor
    Oracle
    Product
    Mysql Connectors
    Vendor
    Oracle
    Product
    Mysql Enterprise Monitor
    Vendor
    Oracle
    Product
    Mysql Server
    Vendor
    Oracle
    Product
    Peoplesoft Enterprise Peopletools
    Vendor
    Oracle
    Product
    Zfs Storage Appliance Kit
    Vendor
    Redhat
    Product
    Acm
    Vendor
    Tenable
    Product
    Nessus Network Monitor
    Vendor
    Tenable
    Product
    Tenable.sc

    Exploits

    No exploit reference

    Related CVEs

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High