Количество 18
Количество 18
GHSA-5ww6-px42-wc85
SM2 Decryption Buffer Overflow
CVE-2021-3711
In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this function twice. The first time, on entry, the "out" parameter can be NULL and, on exit, the "outlen" parameter is populated with the buffer size required to hold the decrypted plaintext. The application can then allocate a sufficiently sized buffer and call EVP_PKEY_decrypt() again, but this time passing a non-NULL value for the "out" parameter. A bug in the implementation of the SM2 decryption code means that the calculation of the buffer size required to hold the plaintext returned by the first call to EVP_PKEY_decrypt() can be smaller than the actual size required by the second call. This can lead to a buffer overflow when EVP_PKEY_decrypt() is called by the application a second time with a buffer that is too small. A malicious attacker who is able present SM2 content for decryption to an application could cause attacker chosen dat...
CVE-2021-3711
In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this function twice. The first time, on entry, the "out" parameter can be NULL and, on exit, the "outlen" parameter is populated with the buffer size required to hold the decrypted plaintext. The application can then allocate a sufficiently sized buffer and call EVP_PKEY_decrypt() again, but this time passing a non-NULL value for the "out" parameter. A bug in the implementation of the SM2 decryption code means that the calculation of the buffer size required to hold the plaintext returned by the first call to EVP_PKEY_decrypt() can be smaller than the actual size required by the second call. This can lead to a buffer overflow when EVP_PKEY_decrypt() is called by the application a second time with a buffer that is too small. A malicious attacker who is able present SM2 content for decryption to an application could cause attacker chosen dat...
CVE-2021-3711
In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this function twice. The first time, on entry, the "out" parameter can be NULL and, on exit, the "outlen" parameter is populated with the buffer size required to hold the decrypted plaintext. The application can then allocate a sufficiently sized buffer and call EVP_PKEY_decrypt() again, but this time passing a non-NULL value for the "out" parameter. A bug in the implementation of the SM2 decryption code means that the calculation of the buffer size required to hold the plaintext returned by the first call to EVP_PKEY_decrypt() can be smaller than the actual size required by the second call. This can lead to a buffer overflow when EVP_PKEY_decrypt() is called by the application a second time with a buffer that is too small. A malicious attacker who is able present SM2 content for decryption to an application could cause attacker chosen data t
CVE-2021-3711
OpenSSL: CVE-2021-3711 SM2 Decryption Buffer Overflow
CVE-2021-3711
In order to decrypt SM2 encrypted data an application is expected to c ...
BDU:2021-04570
Уязвимость реализации криптографического алгоритма SM2 библиотеки OpenSSL, позволяющая нарушителю выполнить произвольный код
openSUSE-SU-2021:2830-1
Security update for openssl-1_1
openSUSE-SU-2021:1188-1
Security update for openssl-1_1
SUSE-SU-2021:2833-1
Security update for openssl-1_1
SUSE-SU-2021:2830-1
Security update for openssl-1_1
ROS-20240412-06
Множественные уязвимости etcd
SUSE-SU-2022:4437-1
Security update for SUSE Manager Client Tools
SUSE-SU-2022:4428-1
Security update for grafana
SUSE-SU-2022:1396-1
Security update for SUSE Manager Client Tools
SUSE-FU-2022:1419-1
Feature update for grafana
SUSE-SU-2022:2134-1
Security update for SUSE Manager Client Tools
ROS-20251016-04
Множественные уязвимости edk2-tools
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-5ww6-px42-wc85 SM2 Decryption Buffer Overflow | CVSS3: 9.8 | 88% Высокий | около 4 лет назад | |
CVE-2021-3711 In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this function twice. The first time, on entry, the "out" parameter can be NULL and, on exit, the "outlen" parameter is populated with the buffer size required to hold the decrypted plaintext. The application can then allocate a sufficiently sized buffer and call EVP_PKEY_decrypt() again, but this time passing a non-NULL value for the "out" parameter. A bug in the implementation of the SM2 decryption code means that the calculation of the buffer size required to hold the plaintext returned by the first call to EVP_PKEY_decrypt() can be smaller than the actual size required by the second call. This can lead to a buffer overflow when EVP_PKEY_decrypt() is called by the application a second time with a buffer that is too small. A malicious attacker who is able present SM2 content for decryption to an application could cause attacker chosen dat... | CVSS3: 9.8 | 88% Высокий | почти 5 лет назад | |
CVE-2021-3711 In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this function twice. The first time, on entry, the "out" parameter can be NULL and, on exit, the "outlen" parameter is populated with the buffer size required to hold the decrypted plaintext. The application can then allocate a sufficiently sized buffer and call EVP_PKEY_decrypt() again, but this time passing a non-NULL value for the "out" parameter. A bug in the implementation of the SM2 decryption code means that the calculation of the buffer size required to hold the plaintext returned by the first call to EVP_PKEY_decrypt() can be smaller than the actual size required by the second call. This can lead to a buffer overflow when EVP_PKEY_decrypt() is called by the application a second time with a buffer that is too small. A malicious attacker who is able present SM2 content for decryption to an application could cause attacker chosen dat... | CVSS3: 9.8 | 88% Высокий | почти 5 лет назад | |
CVE-2021-3711 In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this function twice. The first time, on entry, the "out" parameter can be NULL and, on exit, the "outlen" parameter is populated with the buffer size required to hold the decrypted plaintext. The application can then allocate a sufficiently sized buffer and call EVP_PKEY_decrypt() again, but this time passing a non-NULL value for the "out" parameter. A bug in the implementation of the SM2 decryption code means that the calculation of the buffer size required to hold the plaintext returned by the first call to EVP_PKEY_decrypt() can be smaller than the actual size required by the second call. This can lead to a buffer overflow when EVP_PKEY_decrypt() is called by the application a second time with a buffer that is too small. A malicious attacker who is able present SM2 content for decryption to an application could cause attacker chosen data t | CVSS3: 9.8 | 88% Высокий | почти 5 лет назад | |
CVE-2021-3711 OpenSSL: CVE-2021-3711 SM2 Decryption Buffer Overflow | 88% Высокий | больше 4 лет назад | ||
CVE-2021-3711 In order to decrypt SM2 encrypted data an application is expected to c ... | CVSS3: 9.8 | 88% Высокий | почти 5 лет назад | |
BDU:2021-04570 Уязвимость реализации криптографического алгоритма SM2 библиотеки OpenSSL, позволяющая нарушителю выполнить произвольный код | CVSS3: 9.8 | 88% Высокий | почти 5 лет назад | |
openSUSE-SU-2021:2830-1 Security update for openssl-1_1 | почти 5 лет назад | |||
openSUSE-SU-2021:1188-1 Security update for openssl-1_1 | почти 5 лет назад | |||
SUSE-SU-2021:2833-1 Security update for openssl-1_1 | почти 5 лет назад | |||
SUSE-SU-2021:2830-1 Security update for openssl-1_1 | почти 5 лет назад | |||
ROS-20240412-06 Множественные уязвимости etcd | CVSS3: 9.8 | около 2 лет назад | ||
SUSE-SU-2022:4437-1 Security update for SUSE Manager Client Tools | больше 3 лет назад | |||
SUSE-SU-2022:4428-1 Security update for grafana | больше 3 лет назад | |||
SUSE-SU-2022:1396-1 Security update for SUSE Manager Client Tools | около 4 лет назад | |||
SUSE-FU-2022:1419-1 Feature update for grafana | около 4 лет назад | |||
SUSE-SU-2022:2134-1 Security update for SUSE Manager Client Tools | около 4 лет назад | |||
ROS-20251016-04 Множественные уязвимости edk2-tools | CVSS3: 9.8 | 9 месяцев назад |
Уязвимостей на страницу