CVE Feed

    Dashboard / CVE / CVE-2021-3712

    CVE-2021-3712

    ASN.1 strings are represented internally within OpenSSL as an ASN1_STRING structure which contains a buffer holding the string data and a field holding the buffer length. This contrasts with normal C strings which are repesented as a buffer for the string data which is terminated with a NUL (0) byte. Although not a strict requirement, ASN.1 strings that are parsed using OpenSSL's own "d2i" functions (and other similar parsing functions) as well as any string whose value has been set with the ASN1_STRING_set() function will additionally NUL terminate the byte array in the ASN1_STRING structure. However, it is possible for applications to directly construct valid ASN1_STRING structures which do not NUL terminate the byte array by directly setting the "data" and "length" fields in the ASN1_STRING array. This can also happen by using the ASN1_STRING_set0() function. Numerous OpenSSL functions that print ASN.1 data have been found to assume that the ASN1_STRING byte array will be NUL terminated, even though this is not guaranteed for strings that have been directly constructed. Where an application requests an ASN.1 structure to be printed, and where that ASN.1 structure contains ASN1_STRINGs that have been directly constructed by the application without NUL terminating the "data" field, then a read buffer overrun can occur. The same thing can also occur during name constraints processing of certificates (for example if a certificate has been directly constructed by the application instead of loading it via the OpenSSL parsing functions, and the certificate contains non NUL terminated ASN1_STRING structures). It can also occur in the X509_get1_email(), X509_REQ_get1_email() and X509_get1_ocsp() functions. If a malicious actor can cause an application to directly construct an ASN1_STRING and then process it through one of the affected OpenSSL functions then this issue could be hit. This might result in a crash (causing a Denial of Service attack). It could also result in the disclosure of private memory contents (such as private keys, or sensitive plaintext). Fixed in OpenSSL 1.1.1l (Affected 1.1.1-1.1.1k). Fixed in OpenSSL 1.0.2za (Affected 1.0.2-1.0.2y).

    Published:Aug 24, 2021
    Last Modified:Apr 16, 2026
    EPS:Aug 24, 2021
    EPSS Score:0.00413
    CVSS Score:7.4

    Affected Products

    Vendor
    Debian
    Product
    Debian Linux
    Vendor
    Mcafee
    Product
    Epolicy Orchestrator
    Vendor
    Netapp
    Product
    Clustered Data Ontap
    Vendor
    Netapp
    Product
    Clustered Data Ontap Antivirus Connector
    Vendor
    Netapp
    Product
    E-series Santricity Os Controller
    Vendor
    Netapp
    Product
    Hci Management Node
    Vendor
    Netapp
    Product
    Manageability Software Development Kit
    Vendor
    Netapp
    Product
    Santricity Smi-s Provider
    Vendor
    Netapp
    Product
    Solidfire
    Vendor
    Netapp
    Product
    Storage Encryption
    Vendor
    Openssl
    Product
    Openssl
    Vendor
    Oracle
    Product
    Communications Cloud Native Core Console
    Vendor
    Oracle
    Product
    Communications Cloud Native Core Security Edge Protection Proxy
    Vendor
    Oracle
    Product
    Communications Cloud Native Core Unified Data Repository
    Vendor
    Oracle
    Product
    Communications Session Border Controller
    Vendor
    Oracle
    Product
    Communications Unified Session Manager
    Vendor
    Oracle
    Product
    Enterprise Communications Broker
    Vendor
    Oracle
    Product
    Enterprise Session Border Controller
    Vendor
    Oracle
    Product
    Essbase
    Vendor
    Oracle
    Product
    Health Sciences Inform Publisher
    Vendor
    Oracle
    Product
    Jd Edwards Enterpriseone Tools
    Vendor
    Oracle
    Product
    Jd Edwards World Security
    Vendor
    Oracle
    Product
    Mysql Connectors
    Vendor
    Oracle
    Product
    Mysql Enterprise Monitor
    Vendor
    Oracle
    Product
    Mysql Server
    Vendor
    Oracle
    Product
    Mysql Workbench
    Vendor
    Oracle
    Product
    Peoplesoft Enterprise Peopletools
    Vendor
    Oracle
    Product
    Secure Backup
    Vendor
    Oracle
    Product
    Zfs Storage Appliance Kit
    Vendor
    Redhat
    Product
    Acm
    Vendor
    Redhat
    Product
    Enterprise Linux
    Vendor
    Redhat
    Product
    Jboss Core Services
    Vendor
    Redhat
    Product
    Jboss Enterprise Web Server
    Vendor
    Siemens
    Product
    Sinec Infrastructure Network Services
    Vendor
    Tenable
    Product
    Nessus Network Monitor
    Vendor
    Tenable
    Product
    Tenable.sc

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High