Количество 1 152
Количество 1 152
CVE-2021-3712
ASN.1 strings are represented internally within OpenSSL as an ASN1_STR ...

openSUSE-SU-2020:2269-1
Security update for openssl-1_0_0

openSUSE-SU-2020:2245-1
Security update for openssl-1_1

openSUSE-SU-2020:2236-1
Security update for openssl-1_0_0

openSUSE-SU-2020:2223-1
Security update for openssl-1_1

SUSE-SU-2020:3763-1
Security update for openssl

SUSE-SU-2020:3762-1
Security update for openssl-1_0_0

SUSE-SU-2020:3740-1
Security update for openssl-1_1

SUSE-SU-2020:3732-1
Security update for openssl-1_0_0

SUSE-SU-2020:3722-1
Security update for openssl-1_1

SUSE-SU-2020:3721-1
Security update for openssl-1_1

SUSE-SU-2020:3720-1
Security update for openssl-1_1

SUSE-SU-2020:14560-1
Security update for openssl1
GHSA-whf2-mq76-2fhv
The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrectly when both GENERAL_NAMEs contain an EDIPARTYNAME. A NULL pointer dereference and a crash may occur leading to a possible denial of service attack. OpenSSL itself uses the GENERAL_NAME_cmp function for two purposes: 1) Comparing CRL distribution point names between an available CRL and a CRL distribution point embedded in an X509 certificate 2) When verifying that a timestamp response token signer matches the timestamp authority name (exposed via the API functions TS_RESP_verify_response and TS_RESP_verify_token) If an attacker can control both items being compared then that attacker could trigger a crash. For example if the attacker can trick a client or server into checking a malicious...

CVE-2020-1971
The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrectly when both GENERAL_NAMEs contain an EDIPARTYNAME. A NULL pointer dereference and a crash may occur leading to a possible denial of service attack. OpenSSL itself uses the GENERAL_NAME_cmp function for two purposes: 1) Comparing CRL distribution point names between an available CRL and a CRL distribution point embedded in an X509 certificate 2) When verifying that a timestamp response token signer matches the timestamp authority name (exposed via the API functions TS_RESP_verify_response and TS_RESP_verify_token) If an attacker can control both items being compared then that attacker could trigger a crash. For example if the attacker can trick a client or server into checking a malicious...

CVE-2020-1971
The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrectly when both GENERAL_NAMEs contain an EDIPARTYNAME. A NULL pointer dereference and a crash may occur leading to a possible denial of service attack. OpenSSL itself uses the GENERAL_NAME_cmp function for two purposes: 1) Comparing CRL distribution point names between an available CRL and a CRL distribution point embedded in an X509 certificate 2) When verifying that a timestamp response token signer matches the timestamp authority name (exposed via the API functions TS_RESP_verify_response and TS_RESP_verify_token) If an attacker can control both items being compared then that attacker could trigger a crash. For example if the attacker can trick a client or server into checking a malicious...

CVE-2020-1971
The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrectly when both GENERAL_NAMEs contain an EDIPARTYNAME. A NULL pointer dereference and a crash may occur leading to a possible denial of service attack. OpenSSL itself uses the GENERAL_NAME_cmp function for two purposes: 1) Comparing CRL distribution point names between an available CRL and a CRL distribution point embedded in an X509 certificate 2) When verifying that a timestamp response token signer matches the timestamp authority name (exposed via the API functions TS_RESP_verify_response and TS_RESP_verify_token) If an attacker can control both items being compared then that attacker could trigger a crash. For example if the attacker can trick a client or server into checking a malicious ce
CVE-2020-1971
The X.509 GeneralName type is a generic type for representing differen ...

openSUSE-SU-2021:0476-1
Security update for openssl-1_1

SUSE-SU-2021:0955-2
Security update for openssl-1_1
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
CVE-2021-3712 ASN.1 strings are represented internally within OpenSSL as an ASN1_STR ... | CVSS3: 7.4 | 1% Низкий | почти 4 года назад | |
![]() | openSUSE-SU-2020:2269-1 Security update for openssl-1_0_0 | 0% Низкий | больше 4 лет назад | |
![]() | openSUSE-SU-2020:2245-1 Security update for openssl-1_1 | 0% Низкий | больше 4 лет назад | |
![]() | openSUSE-SU-2020:2236-1 Security update for openssl-1_0_0 | 0% Низкий | больше 4 лет назад | |
![]() | openSUSE-SU-2020:2223-1 Security update for openssl-1_1 | 0% Низкий | больше 4 лет назад | |
![]() | SUSE-SU-2020:3763-1 Security update for openssl | 0% Низкий | больше 4 лет назад | |
![]() | SUSE-SU-2020:3762-1 Security update for openssl-1_0_0 | 0% Низкий | больше 4 лет назад | |
![]() | SUSE-SU-2020:3740-1 Security update for openssl-1_1 | 0% Низкий | больше 4 лет назад | |
![]() | SUSE-SU-2020:3732-1 Security update for openssl-1_0_0 | 0% Низкий | больше 4 лет назад | |
![]() | SUSE-SU-2020:3722-1 Security update for openssl-1_1 | 0% Низкий | больше 4 лет назад | |
![]() | SUSE-SU-2020:3721-1 Security update for openssl-1_1 | 0% Низкий | больше 4 лет назад | |
![]() | SUSE-SU-2020:3720-1 Security update for openssl-1_1 | 0% Низкий | больше 4 лет назад | |
![]() | SUSE-SU-2020:14560-1 Security update for openssl1 | 0% Низкий | больше 4 лет назад | |
GHSA-whf2-mq76-2fhv The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrectly when both GENERAL_NAMEs contain an EDIPARTYNAME. A NULL pointer dereference and a crash may occur leading to a possible denial of service attack. OpenSSL itself uses the GENERAL_NAME_cmp function for two purposes: 1) Comparing CRL distribution point names between an available CRL and a CRL distribution point embedded in an X509 certificate 2) When verifying that a timestamp response token signer matches the timestamp authority name (exposed via the API functions TS_RESP_verify_response and TS_RESP_verify_token) If an attacker can control both items being compared then that attacker could trigger a crash. For example if the attacker can trick a client or server into checking a malicious... | CVSS3: 5.9 | 0% Низкий | около 3 лет назад | |
![]() | CVE-2020-1971 The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrectly when both GENERAL_NAMEs contain an EDIPARTYNAME. A NULL pointer dereference and a crash may occur leading to a possible denial of service attack. OpenSSL itself uses the GENERAL_NAME_cmp function for two purposes: 1) Comparing CRL distribution point names between an available CRL and a CRL distribution point embedded in an X509 certificate 2) When verifying that a timestamp response token signer matches the timestamp authority name (exposed via the API functions TS_RESP_verify_response and TS_RESP_verify_token) If an attacker can control both items being compared then that attacker could trigger a crash. For example if the attacker can trick a client or server into checking a malicious... | CVSS3: 5.9 | 0% Низкий | больше 4 лет назад |
![]() | CVE-2020-1971 The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrectly when both GENERAL_NAMEs contain an EDIPARTYNAME. A NULL pointer dereference and a crash may occur leading to a possible denial of service attack. OpenSSL itself uses the GENERAL_NAME_cmp function for two purposes: 1) Comparing CRL distribution point names between an available CRL and a CRL distribution point embedded in an X509 certificate 2) When verifying that a timestamp response token signer matches the timestamp authority name (exposed via the API functions TS_RESP_verify_response and TS_RESP_verify_token) If an attacker can control both items being compared then that attacker could trigger a crash. For example if the attacker can trick a client or server into checking a malicious... | CVSS3: 5.9 | 0% Низкий | больше 4 лет назад |
![]() | CVE-2020-1971 The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrectly when both GENERAL_NAMEs contain an EDIPARTYNAME. A NULL pointer dereference and a crash may occur leading to a possible denial of service attack. OpenSSL itself uses the GENERAL_NAME_cmp function for two purposes: 1) Comparing CRL distribution point names between an available CRL and a CRL distribution point embedded in an X509 certificate 2) When verifying that a timestamp response token signer matches the timestamp authority name (exposed via the API functions TS_RESP_verify_response and TS_RESP_verify_token) If an attacker can control both items being compared then that attacker could trigger a crash. For example if the attacker can trick a client or server into checking a malicious ce | CVSS3: 5.9 | 0% Низкий | больше 4 лет назад |
CVE-2020-1971 The X.509 GeneralName type is a generic type for representing differen ... | CVSS3: 5.9 | 0% Низкий | больше 4 лет назад | |
![]() | openSUSE-SU-2021:0476-1 Security update for openssl-1_1 | 13% Средний | около 4 лет назад | |
![]() | SUSE-SU-2021:0955-2 Security update for openssl-1_1 | 13% Средний | почти 3 года назад |
Уязвимостей на страницу