USN-4745-1
Dashboard / Vulnerabilities / USN-4745-1
USN-4745-1
Summary: openssl vulnerabilities
Details: David Benjamin discovered that OpenSSL incorrectly handled comparing certificates containing a EDIPartyName name type. A remote attacker could possibly use this issue to cause OpenSSL to crash, resulting in a denial of service. (CVE-2020-1971) Tavis Ormandy discovered that OpenSSL incorrectly handled parsing issuer fields. A remote attacker could possibly use this issue to cause OpenSSL to crash, resulting in a denial of service. (CVE-2021-23841)
References: https://ubuntu.com/security/notices/USN-4745-1, https://ubuntu.com/security/CVE-2020-1971, https://ubuntu.com/security/CVE-2021-23841
Affected packages
Package
Name: openssl
Purl: pkg:deb/ubuntu/openssl?arch=source&distro=trusty%2Fesm
Affected ranges
Type: ECOSYSTEM
Events:
