CVE-2021-23841 Details
Description
The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash value based on the issuer and serial number data contained within an X509 certificate. However it fails to correctly handle any errors that may occur while parsing the issuer field (which might occur if the issuer field is maliciously constructed). This may subsequently result in a NULL pointer deref and a crash leading to a potential denial of service attack. The function X509_issuer_and_serial_hash() is never directly called by OpenSSL itself so applications are only vulnerable if they use this function directly and they use it on certificates that may have been obtained from untrusted sources. OpenSSL versions 1.1.1i and below are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1j. OpenSSL versions 1.0.2x and below are affected by this issue. However OpenSSL 1.0.2 is out of support and no longer receiving public updates. Premium support customers of OpenSSL 1.0.2 should upgrade to 1.0.2y. Other users should upgrade to 1.1.1j. Fixed in OpenSSL 1.1.1j (Affected 1.1.1-1.1.1i). Fixed in OpenSSL 1.0.2y (Affected 1.0.2-1.0.2x).
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 26, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-476 | NULL Pointer Dereference | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| openssl openssl | >= 1.0.2, < 1.0.2y >= 1.1.1, < 1.1.1j |
CPE
Remediation
| |
| debian debian linux | 10.0 |
CPE
Remediation
| |
| tenable nessus network monitor | 5.11.0 5.11.1 5.12.0 5.12.1 5.13.0 |
CPE
Remediation
| |
| tenable tenable.sc | >= 5.13.0, <= 5.17.0 |
CPE
Remediation
| |
| apple safari | < 14.1.1 |
CPE
Remediation
| |
| apple ipados | < 14.6 |
CPE
Remediation
| |
| apple iphone os | < 14.6 |
CPE
Remediation
| |
| apple macos | >= 11.1, < 11.4 |
CPE
Remediation
| |
| netapp oncommand insight | All versions |
CPE
Remediation
| |
| netapp oncommand workflow automation | All versions |
CPE
Remediation
| |
| netapp snapcenter | All versions |
CPE
Remediation
| |
| oracle business intelligence | 5.5.0.0.0 5.9.0.0.0 12.2.1.3.0 12.2.1.4.0 |
CPE
Remediation
| |
| oracle communications cloud native core policy | 1.15.0 |
CPE
Remediation
| |
| oracle enterprise manager for storage management | 13.4.0.0 |
CPE
Remediation
| |
| oracle enterprise manager ops center | 12.4.0.0 |
CPE
Remediation
| |
| oracle essbase | 21.2 |
CPE
Remediation
| |
| oracle graalvm | 19.3.5 20.3.1.2 21.0.0.2 |
CPE
Remediation
| |
| oracle jd edwards world security | a9.4 |
CPE
Remediation
| |
| oracle mysql enterprise monitor | < 8.0.23 |
CPE
Remediation
| |
| oracle mysql server | < 5.7.33 >= 8.0.15, < 8.0.23 |
CPE
Remediation
| |
| oracle peoplesoft enterprise peopletools | 8.57 8.58 8.59 |
CPE
Remediation
| |
| oracle zfs storage appliance kit | 8.8 |
CPE
Remediation
| |
| siemens sinec ins | < 1.0 1.0 - 1.0 sp1 |
CPE
Remediation
| |
Change History
31 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| Jun 21, 2024 | CVE Modified | [email protected] |
| May 14, 2024 | CVE Modified | [email protected] |
| Nov 7, 2023 | CVE Modified | [email protected] |
| Jan 9, 2023 | CPE Deprecation Remap | [email protected] |
| Oct 7, 2022 | Modified Analysis | [email protected] |
| Sep 13, 2022 | CVE Modified | [email protected] |
| May 12, 2022 | Modified Analysis | [email protected] |
| May 3, 2022 | CWE Remap | [email protected] |
| Apr 20, 2022 | CVE Modified | [email protected] |
| Dec 10, 2021 | Modified Analysis | [email protected] |
| Oct 20, 2021 | CVE Modified | [email protected] |
| Jul 20, 2021 | CVE Modified | [email protected] |
| Jul 14, 2021 | CVE Modified | [email protected] |
| Jun 17, 2021 | Modified Analysis | [email protected] |
| Jun 14, 2021 | CVE Modified | [email protected] |
| May 26, 2021 | CVE Modified | [email protected] |
| May 26, 2021 | Modified Analysis | [email protected] |
| May 25, 2021 | CVE Modified | [email protected] |
| May 24, 2021 | CVE Modified | [email protected] |
| May 13, 2021 | CVE Modified | [email protected] |
| May 11, 2021 | CVE Modified | [email protected] |
| Mar 31, 2021 | CVE Modified | [email protected] |
| Mar 10, 2021 | Modified Analysis | [email protected] |
| Mar 2, 2021 | CVE Modified | [email protected] |
| Feb 25, 2021 | Initial Analysis | [email protected] |
| Feb 19, 2021 | CVE Modified | [email protected] |
| Feb 18, 2021 | CVE Modified | [email protected] |
| Feb 17, 2021 | CVE Modified | [email protected] |