Логотип exploitDog
bind:"BDU:2021-01844" OR bind:"CVE-2021-3449"
Консоль
Логотип exploitDog

exploitDog

bind:"BDU:2021-01844" OR bind:"CVE-2021-3449"

Количество 21

Количество 21

fstec логотип

BDU:2021-01844

больше 7 лет назад

Уязвимость реализации протокола TLS библиотеки OpenSSL, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.9
EPSS: Средний
ubuntu логотип

CVE-2021-3449

больше 4 лет назад

An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer dereference will result, leading to a crash and a denial of service attack. A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which is the default configuration). OpenSSL TLS clients are not impacted by this issue. All OpenSSL 1.1.1 versions are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1k. OpenSSL 1.0.2 is not impacted by this issue. Fixed in OpenSSL 1.1.1k (Affected 1.1.1-1.1.1j).

CVSS3: 5.9
EPSS: Средний
redhat логотип

CVE-2021-3449

больше 4 лет назад

An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer dereference will result, leading to a crash and a denial of service attack. A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which is the default configuration). OpenSSL TLS clients are not impacted by this issue. All OpenSSL 1.1.1 versions are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1k. OpenSSL 1.0.2 is not impacted by this issue. Fixed in OpenSSL 1.1.1k (Affected 1.1.1-1.1.1j).

CVSS3: 5.9
EPSS: Средний
nvd логотип

CVE-2021-3449

больше 4 лет назад

An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer dereference will result, leading to a crash and a denial of service attack. A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which is the default configuration). OpenSSL TLS clients are not impacted by this issue. All OpenSSL 1.1.1 versions are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1k. OpenSSL 1.0.2 is not impacted by this issue. Fixed in OpenSSL 1.1.1k (Affected 1.1.1-1.1.1j).

CVSS3: 5.9
EPSS: Средний
msrc логотип

CVE-2021-3449

почти 4 года назад

OpenSSL: CVE-2021-3449 NULL pointer deref in signature_algorithms processing

EPSS: Средний
debian логотип

CVE-2021-3449

больше 4 лет назад

An OpenSSL TLS server may crash if sent a maliciously crafted renegoti ...

CVSS3: 5.9
EPSS: Средний
suse-cvrf логотип

openSUSE-SU-2021:0476-1

больше 4 лет назад

Security update for openssl-1_1

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2021:0955-2

около 3 лет назад

Security update for openssl-1_1

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2021:0955-1

больше 4 лет назад

Security update for openssl-1_1

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2021:0954-1

больше 4 лет назад

Security update for openssl-1_1

EPSS: Средний
github логотип

GHSA-83mx-573x-5rw9

почти 4 года назад

openssl-src NULL pointer Dereference in signature_algorithms processing

CVSS3: 5.9
EPSS: Средний
oracle-oval логотип

ELSA-2021-9151

больше 4 лет назад

ELSA-2021-9151: openssl security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2021-1024

больше 4 лет назад

ELSA-2021-1024: openssl security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:2353-1

около 4 лет назад

Security update for nodejs10

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:2327-1

около 4 лет назад

Security update for nodejs12

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:1061-1

около 4 лет назад

Security update for nodejs10

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:1059-1

около 4 лет назад

Security update for nodejs12

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:2353-1

около 4 лет назад

Security update for nodejs10

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:2327-1

около 4 лет назад

Security update for nodejs12

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:2326-1

около 4 лет назад

Security update for nodejs12

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2021-01844

Уязвимость реализации протокола TLS библиотеки OpenSSL, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.9
13%
Средний
больше 7 лет назад
ubuntu логотип
CVE-2021-3449

An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer dereference will result, leading to a crash and a denial of service attack. A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which is the default configuration). OpenSSL TLS clients are not impacted by this issue. All OpenSSL 1.1.1 versions are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1k. OpenSSL 1.0.2 is not impacted by this issue. Fixed in OpenSSL 1.1.1k (Affected 1.1.1-1.1.1j).

CVSS3: 5.9
13%
Средний
больше 4 лет назад
redhat логотип
CVE-2021-3449

An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer dereference will result, leading to a crash and a denial of service attack. A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which is the default configuration). OpenSSL TLS clients are not impacted by this issue. All OpenSSL 1.1.1 versions are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1k. OpenSSL 1.0.2 is not impacted by this issue. Fixed in OpenSSL 1.1.1k (Affected 1.1.1-1.1.1j).

CVSS3: 5.9
13%
Средний
больше 4 лет назад
nvd логотип
CVE-2021-3449

An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer dereference will result, leading to a crash and a denial of service attack. A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which is the default configuration). OpenSSL TLS clients are not impacted by this issue. All OpenSSL 1.1.1 versions are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1k. OpenSSL 1.0.2 is not impacted by this issue. Fixed in OpenSSL 1.1.1k (Affected 1.1.1-1.1.1j).

CVSS3: 5.9
13%
Средний
больше 4 лет назад
msrc логотип
CVE-2021-3449

OpenSSL: CVE-2021-3449 NULL pointer deref in signature_algorithms processing

13%
Средний
почти 4 года назад
debian логотип
CVE-2021-3449

An OpenSSL TLS server may crash if sent a maliciously crafted renegoti ...

CVSS3: 5.9
13%
Средний
больше 4 лет назад
suse-cvrf логотип
openSUSE-SU-2021:0476-1

Security update for openssl-1_1

13%
Средний
больше 4 лет назад
suse-cvrf логотип
SUSE-SU-2021:0955-2

Security update for openssl-1_1

13%
Средний
около 3 лет назад
suse-cvrf логотип
SUSE-SU-2021:0955-1

Security update for openssl-1_1

13%
Средний
больше 4 лет назад
suse-cvrf логотип
SUSE-SU-2021:0954-1

Security update for openssl-1_1

13%
Средний
больше 4 лет назад
github логотип
GHSA-83mx-573x-5rw9

openssl-src NULL pointer Dereference in signature_algorithms processing

CVSS3: 5.9
13%
Средний
почти 4 года назад
oracle-oval логотип
ELSA-2021-9151

ELSA-2021-9151: openssl security update (IMPORTANT)

больше 4 лет назад
oracle-oval логотип
ELSA-2021-1024

ELSA-2021-1024: openssl security update (IMPORTANT)

больше 4 лет назад
suse-cvrf логотип
openSUSE-SU-2021:2353-1

Security update for nodejs10

около 4 лет назад
suse-cvrf логотип
openSUSE-SU-2021:2327-1

Security update for nodejs12

около 4 лет назад
suse-cvrf логотип
openSUSE-SU-2021:1061-1

Security update for nodejs10

около 4 лет назад
suse-cvrf логотип
openSUSE-SU-2021:1059-1

Security update for nodejs12

около 4 лет назад
suse-cvrf логотип
SUSE-SU-2021:2353-1

Security update for nodejs10

около 4 лет назад
suse-cvrf логотип
SUSE-SU-2021:2327-1

Security update for nodejs12

около 4 лет назад
suse-cvrf логотип
SUSE-SU-2021:2326-1

Security update for nodejs12

около 4 лет назад

Уязвимостей на страницу