CVE-2021-23841
Description
The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash value based on the issuer and serial number data contained within an X509 certificate. However it fails to correctly handle any errors that may occur while parsing the issuer field (which might occur if the issuer field is maliciously constructed). This may subsequently result in a NULL pointer deref and a crash leading to a potential denial of service attack. The function X509_issuer_and_serial_hash() is never directly called by OpenSSL itself so applications are only vulnerable if they use this function directly and they use it on certificates that may have been obtained from untrusted sources. OpenSSL versions 1.1.1i and below are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1j. OpenSSL versions 1.0.2x and below are affected by this issue. However OpenSSL 1.0.2 is out of support and no longer receiving public updates. Premium support customers of OpenSSL 1.0.2 should upgrade to 1.0.2y. Other users should upgrade to 1.1.1j. Fixed in OpenSSL 1.1.1j (Affected 1.1.1-1.1.1i). Fixed in OpenSSL 1.0.2y (Affected 1.0.2-1.0.2x).
Risk Information
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Vulnerabilities CVE-2021-23841,CVE-2021-23840,CVE-2021-3712 are fixed in OpenSSL 1.1.1j | Windows |
| Vulnerabilities CVE-2021-23841,CVE-2021-23840,CVE-2021-3712 are fixed in OpenSSL (x64) 1.1.1j | Windows |
| Multiple Vulnerabilities are affected in Mysql 8.0.23 | Windows |
| Vulnerabilities CVE-2021-23840,CVE-2021-23841,CVE-2021-20077 are fixed in Nessus Agent (8.2.3.20045) | Windows |
| Vulnerabilities CVE-2021-23840,CVE-2021-23841,CVE-2021-20077 are fixed in Nessus Agent (x64) (8.2.3.20045) | Windows |
| Multiple vulnerabilities are affected in Mysql 5.7.33 | Windows |
| Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.1.7 | Windows |
| Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.2.4 | Windows |
| Multiple Vulnerabilities are affected in IBM Cognos Analytics 12.0.1 | Windows |
| Multiple Vulnerabilities are affected in Netapp Oncommand Insight 2.3 | Windows |
| Vulnerabilities CVE-2021-2161,CVE-2021-2163,CVE-2021-23841,CVE-2021-3450 are affected in Oracle GraalVM Enterprise Edition 19.3.5 | Windows |
| Vulnerabilities CVE-2021-2161,CVE-2021-2163,CVE-2021-23841,CVE-2021-3450 are affected in Oracle GraalVM Enterprise Edition 20.3.1.2 | Windows |
| Vulnerabilities CVE-2021-2161,CVE-2021-2163,CVE-2021-23841,CVE-2021-3450 are affected in Oracle GraalVM Enterprise Edition 21.0.0.2 | Windows |
| Multiple Vulnerabilities are affected in IBM Security Guardium 11.1 | Windows |
| Multiple Vulnerabilities are affected in IBM Security Guardium 11.2 | Windows |
| Multiple Vulnerabilities are affected in IBM Security Guardium 11.3 | Windows |
| Multiple Vulnerabilities are affected in IBM Security Guardium 11.4 | Windows |
| Multiple Vulnerabilities are affected in Netapp Snapcenter 2.3 | Windows |
| Multiple Vulnerabilities are affected in Netapp Oncommand Workflow Automation 2.3 | Windows |
| Multiple Vulnerabilities are affected in Nessus Network Monitor 5.13.0 | Windows |
| Multiple Vulnerabilities are affected in Nessus Network Monitor 5.11.0 | Windows |
| Multiple Vulnerabilities are affected in Nessus Network Monitor 5.11.1 | Windows |
| Multiple Vulnerabilities are affected in Nessus Network Monitor 5.12.0 | Windows |
| Vulnerabilities CVE-2021-23840,CVE-2021-23841,CVE-2021-3449,CVE-2021-3450 are affected in Nessus Network Monitor 5.12.1 | Windows |
| Vulnerabilities CVE-2021-23841 are affected in Apple Safari 14.1.0 | Windows |
| Multiple Vulnerabilities are affected in IBM Security Guardium 11.0 | Windows |
| Multiple vulnerabilities are fixed in MacOS Big Sur 11.4 - Software Update | Mac |
| Vulnerabilities CVE-2021-23841 are affected in Apple Safari for MAC 14.1.0 | Mac |
| openssl security update(DSA-4855-1) openssl_1.1.1d-0+deb10u5_i386.deb | Linux |
| openssl security update(DSA-4855-1) openssl_1.1.1d-0+deb10u5_amd64.deb | Linux |
| Secure Socket Layer (SSL) cryptographic library and tools (USN-4738-1) libssl1.1_1.1.1f-1ubuntu2.2_i386.deb | Linux |
| Secure Socket Layer (SSL) cryptographic library and tools (USN-4738-1) libssl1.1_1.1.1f-1ubuntu2.2_amd64.deb | Linux |
| Secure Socket Layer (SSL) cryptographic library and tools (USN-4738-1) libssl1.1_1.1.1f-1ubuntu4.2_i386.deb | Linux |
| Secure Socket Layer (SSL) cryptographic library and tools (USN-4738-1) libssl1.1_1.1.1f-1ubuntu4.2_amd64.deb | Linux |
| Secure Socket Layer (SSL) cryptographic library and tools (USN-4738-1) libssl1.1_1.1.1-1ubuntu2.1~18.04.8_i386.deb | Linux |
| Secure Socket Layer (SSL) cryptographic library and tools (USN-4738-1) libssl1.1_1.1.1-1ubuntu2.1~18.04.8_amd64.deb | Linux |
| Secure Socket Layer (SSL) cryptographic library and tools (USN-4738-1) libssl1.0.0_1.0.2n-1ubuntu5.6_i386.deb | Linux |
| Secure Socket Layer (SSL) cryptographic library and tools (USN-4738-1) libssl1.0.0_1.0.2n-1ubuntu5.6_amd64.deb | Linux |
| Secure Socket Layer (SSL) cryptographic library and tools (USN-4738-1) libssl1.0.0_1.0.2g-1ubuntu4.19_i386.deb | Linux |
| Secure Socket Layer (SSL) cryptographic library and tools (USN-4738-1) libssl1.0.0_1.0.2g-1ubuntu4.19_amd64.deb | Linux |
| SUSE-SU-2021:0752-1(SUSE Linux Enterprise Server 12-SP5 ) libopenssl1_1-1.1.1d-2.30.1.x86_64.rpm | Linux |
| SUSE-SU-2021:0752-1(SUSE Linux Enterprise Server 12-SP5 ) libopenssl1_1-32bit-1.1.1d-2.30.1.x86_64.rpm | Linux |
| SUSE-SU-2021:0752-1(SUSE Linux Enterprise Server 12-SP5 ) libopenssl1_1-debuginfo-1.1.1d-2.30.1.x86_64.rpm | Linux |
| SUSE-SU-2021:0752-1(SUSE Linux Enterprise Server 12-SP5 ) libopenssl1_1-debuginfo-32bit-1.1.1d-2.30.1.x86_64.rpm | Linux |
| SUSE-SU-2021:0752-1(SUSE Linux Enterprise Server 12-SP5 ) openssl-1_1-1.1.1d-2.30.1.x86_64.rpm | Linux |
| SUSE-SU-2021:0752-1(SUSE Linux Enterprise Server 12-SP5 ) openssl-1_1-debuginfo-1.1.1d-2.30.1.x86_64.rpm | Linux |
| SUSE-SU-2021:0752-1(SUSE Linux Enterprise Server 12-SP5 ) openssl-1_1-debugsource-1.1.1d-2.30.1.x86_64.rpm | Linux |
| (RHSA-2021:3798) openssl security update openssl-1.0.2k-22.el7_9.x86_64.rpm | Linux |
| (RHSA-2021:3798) openssl security update openssl-devel-1.0.2k-22.el7_9.i686.rpm | Linux |
| (RHSA-2021:3798) openssl security update openssl-devel-1.0.2k-22.el7_9.x86_64.rpm | Linux |
| (RHSA-2021:3798) openssl security update openssl-libs-1.0.2k-22.el7_9.i686.rpm | Linux |
| (RHSA-2021:3798) openssl security update openssl-libs-1.0.2k-22.el7_9.x86_64.rpm | Linux |
| (RHSA-2021:3798) openssl security update openssl-perl-1.0.2k-22.el7_9.x86_64.rpm | Linux |
| (RHSA-2021:3798) openssl security update openssl-static-1.0.2k-22.el7_9.i686.rpm | Linux |
| (RHSA-2021:3798) openssl security update openssl-static-1.0.2k-22.el7_9.x86_64.rpm | Linux |
| Openssl update (ELSA-2021-3798) openssl-1.0.2k-22.el7_9.x86_64.rpm | Linux |
| Openssl-devel update (ELSA-2021-3798) openssl-devel-1.0.2k-22.el7_9.i686.rpm | Linux |
| Openssl-devel update (ELSA-2021-3798) openssl-devel-1.0.2k-22.el7_9.x86_64.rpm | Linux |
| Openssl-libs update (ELSA-2021-3798) openssl-libs-1.0.2k-22.el7_9.i686.rpm | Linux |
| Openssl-libs update (ELSA-2021-3798) openssl-libs-1.0.2k-22.el7_9.x86_64.rpm | Linux |
| Openssl-perl update (ELSA-2021-3798) openssl-perl-1.0.2k-22.el7_9.x86_64.rpm | Linux |
| Openssl-static update (ELSA-2021-3798) openssl-static-1.0.2k-22.el7_9.i686.rpm | Linux |
| Openssl-static update (ELSA-2021-3798) openssl-static-1.0.2k-22.el7_9.x86_64.rpm | Linux |
| Secure Socket Layer (SSL) cryptographic library and tools (USN-4745-1) libssl1.0.0_1.0.1-4ubuntu5.45_i386.deb | Linux |
| Secure Socket Layer (SSL) cryptographic library and tools (USN-4745-1) libssl1.0.0_1.0.1-4ubuntu5.45_amd64.deb | Linux |
| NULL Pointer Dereference Vulnerability (CVE-2021-23841) | NCM |
Patch Details
Click to see the patches provided by ManageEngine for this CVE
| Patch ID | Patch Description |
|---|---|
| PATCH-337447 | Nessus Agent (10.6.1) |
| PATCH-337448 | Nessus Agent (x64) (10.6.1) |
| PATCH-605752 | MacOS Big Sur 11.7.10 - Software Update (Force Reboot)(CVE-2023-41064) |
| PATCH-612606 | Apple Safari for MAC (MacOS Sequoia) (26.1) |
References
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234