CVE-2021-3449
MEDIUM5.9EPSS 9.9%NULL pointer deref in signature_algorithms processing
Published: 8/25/2021Modified: 12/16/2024
Also known as:GHSA-83mx-573x-5rw9ALPINE-CVE-2021-3449BIT-node-2021-3449BIT-node-min-2021-3449RUSTSEC-2021-0055
Description
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer dereference will result, leading to a crash and a denial of service attack. A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which is the default configuration). OpenSSL TLS clients are not impacted by this issue.
Affected packages (8)
- Alpine/opensslfrom 0, < 1.1.1k-r0
- Alpine/openssl3from 0, < 1.1.1k-r0
- Bitnami/node>= 10.0.0, < 10.12.1, >= 10.13.0, < 10.24.1, >= 12.0.0, < 12.12.1, >= 12.13.0, < 12.22.1, >= 14.0.0, < 14.14.1, >= 14.15.0, < 14.16.1, >= 15.0.0, < 15.14.0
- Bitnami/node-min>= 10.0.0, < 10.12.1, >= 10.13.0, < 10.24.1, >= 12.0.0, < 12.12.1, >= 12.13.0, < 12.22.1, >= 14.0.0, < 14.14.1, >= 14.15.0, < 14.16.1, >= 15.0.0, < 15.14.0
- crates.io/openssl-src>= 0.0.0-0, < 111.15.0
- crates.io/openssl-srcfrom 0, < 111.15.0
- Debian/opensslfrom 0, < 1.1.1d-0+deb10u6
- Debian/opensslfrom 0, < 1.1.1k-1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.9 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H |
References (40)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2021-3449
- ADVISORYhttps://security.alpinelinux.org/vuln/CVE-2021-3449
- ADVISORYhttps://security-tracker.debian.org/tracker/CVE-2021-3449
- PATCHhttps://crates.io/crates/openssl-src
- PATCHhttps://github.com/alexcrichton/openssl-src-rs
- WEBhttps://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf
- WEBhttps://cert-portal.siemens.com/productcert/pdf/ssa-772220.pdf
- WEBhttps://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=fb9fa6b51defd48157eeb207f52181f735d96148
- WEBhttps://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=fb9fa6b51defd48157eeb207f52181f735d96148
- WEBhttps://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44845
- WEBhttps://kc.mcafee.com/corporate/index?page=content&id=SB10356
- WEBhttps://lists.debian.org/debian-lts-announce/2021/08/msg00029.html
- WEBhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CCBFLLVQVILIVGZMBJL3IXZGKWQISYNP/
- WEBhttps://lists.fedoraproject.org/archives/list/[email protected]/message/CCBFLLVQVILIVGZMBJL3IXZGKWQISYNP
- WEBhttps://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0013
- WEBhttps://rustsec.org/advisories/RUSTSEC-2021-0055
- WEBhttps://rustsec.org/advisories/RUSTSEC-2021-0055.html
- WEBhttps://security.FreeBSD.org/advisories/FreeBSD-SA-21:07.openssl.asc
- WEBhttps://security.gentoo.org/glsa/202103-03
- WEBhttps://security.netapp.com/advisory/ntap-20210326-0006
- WEBhttps://security.netapp.com/advisory/ntap-20210326-0006/
- WEBhttps://security.netapp.com/advisory/ntap-20210513-0002
- WEBhttps://security.netapp.com/advisory/ntap-20210513-0002/
- WEBhttps://security.netapp.com/advisory/ntap-20240621-0006/
- WEBhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-openssl-2021-GHY28dJd
- WEBhttps://www.debian.org/security/2021/dsa-4875
- WEBhttps://www.openssl.org/news/secadv/20210325.txt
- WEBhttps://www.oracle.com/security-alerts/cpuApr2021.html
- WEBhttps://www.oracle.com/security-alerts/cpuapr2022.html
- WEBhttps://www.oracle.com//security-alerts/cpujul2021.html
- WEBhttps://www.oracle.com/security-alerts/cpujul2022.html
- WEBhttps://www.oracle.com/security-alerts/cpuoct2021.html
- WEBhttps://www.tenable.com/security/tns-2021-05
- WEBhttps://www.tenable.com/security/tns-2021-06
- WEBhttps://www.tenable.com/security/tns-2021-09
- WEBhttps://www.tenable.com/security/tns-2021-10
- WEBhttp://www.openwall.com/lists/oss-security/2021/03/27/1
- WEBhttp://www.openwall.com/lists/oss-security/2021/03/27/2
- WEBhttp://www.openwall.com/lists/oss-security/2021/03/28/3
- WEBhttp://www.openwall.com/lists/oss-security/2021/03/28/4