OpenSSL Multiple Denial of Service Vulnerabilities

Bug #1915913 reported by it0001
258
This bug affects 1 person
Affects Status Importance Assigned to Milestone
openssl (Ubuntu)
Fix Released
Undecided
Unassigned

Bug Description

Multiple vulnerabilities have been reported in OpenSSL, which can be exploited by malicious people to cause a DoS (Denial of Service).

1

An error related to the "X509_issuer_and_serial_hash()" function (crypto/x509/x509_cmp.c) can be exploited to trigger a NULL pointer dereference and subsequently cause a crash.

2

An integer overflow error related to CipherUpdate calls can be exploited to cause a crash.

The vulnerabilities are reported in versions prior to 1.1.1j and prior to 1.0.2y.

Affected Software

The following software is affected by the described vulnerability. Please check the vendor links below to see if exactly your version is affected.

OpenSSL 1.x

Solution

Update to version 1.1.1j or 1.0.2y.

References

1. https://www.openssl.org/news/secadv/20210216.txt <https://www.openssl.org/news/secadv/20210216.txt>
2. https://github.com/openssl/openssl/commit/8130d654d1de922ea224fa18ee3bc7262edc39c0 <https://github.com/openssl/openssl/commit/8130d654d1de922ea224fa18ee3bc7262edc39c0>
3. https://github.com/openssl/openssl/commit/c9fb704cf3af5524eb8e79961e31b60eee8c3c47 <https://github.com/openssl/openssl/commit/c9fb704cf3af5524eb8e79961e31b60eee8c3c47>

Please provide an update.

Revision history for this message
Seth Arnold (seth-arnold) wrote :

Hello, there are untested packages in https://launchpad.net/~ubuntu-security-proposed/+archive/ubuntu/ppa/+packages in case you wish to test them in your environment.

Thanks

information type: Private Security → Public Security
Revision history for this message
Marc Deslauriers (mdeslaur) wrote :

Updated for this issue have been released:

https://ubuntu.com/security/notices/USN-4738-1

Changed in openssl (Ubuntu):
status: New → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.