CVE-2021-3449

Related Vulnerabilities: CVE-2021-3449  

A flaw was found in openssl. A server crash and denial of service attack could occur if a client sends a TLSv1.2 renegotiation ClientHello and omits the signature_algorithms extension but includes a signature_algorithms_cert extension. The highest threat from this vulnerability is to system availability.

Description

A flaw was found in openssl. A server crash and denial of service attack could occur if a client sends a TLSv1.2 renegotiation ClientHello and omits the signature_algorithms extension but includes a signature_algorithms_cert extension. The highest threat from this vulnerability is to system availability.

Statement

This flaw only affects OpenSSL 1.1.1, older versions are not affected.

This flaw only affects OpenSSL 1.1.1, older versions are not affected.

Additional Information

  • Bugzilla 1941554: CVE-2021-3449 openssl: NULL pointer deref in signature_algorithms processing
  • FAQ: Frequently asked questions about CVE-2021-3449