An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signaturealgorithms extension (where it was present in the initial ClientHello), but includes a signaturealgorithms_cert extension then a NULL pointer dereference will result, leading to a crash and a denial of service attack. A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which is the default configuration). OpenSSL TLS clients are not impacted by this issue. All OpenSSL 1.1.1 versions are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1k. OpenSSL 1.0.2 is not impacted by this issue. Fixed in OpenSSL 1.1.1k (Affected 1.1.1-1.1.1j).
{ "ubuntu_priority": "high", "binaries": [ { "binary_name": "libcrypto1.0.0-udeb", "binary_version": "1.0.2g-1ubuntu4.19" }, { "binary_name": "libcrypto1.0.0-udeb-dbgsym", "binary_version": "1.0.2g-1ubuntu4.19" }, { "binary_name": "libssl-dev", "binary_version": "1.0.2g-1ubuntu4.19" }, { "binary_name": "libssl-dev-dbgsym", "binary_version": "1.0.2g-1ubuntu4.19" }, { "binary_name": "libssl-doc", "binary_version": "1.0.2g-1ubuntu4.19" }, { "binary_name": "libssl1.0.0", "binary_version": "1.0.2g-1ubuntu4.19" }, { "binary_name": "libssl1.0.0-dbg", "binary_version": "1.0.2g-1ubuntu4.19" }, { "binary_name": "libssl1.0.0-dbgsym", "binary_version": "1.0.2g-1ubuntu4.19" }, { "binary_name": "libssl1.0.0-udeb", "binary_version": "1.0.2g-1ubuntu4.19" }, { "binary_name": "libssl1.0.0-udeb-dbgsym", "binary_version": "1.0.2g-1ubuntu4.19" }, { "binary_name": "openssl", "binary_version": "1.0.2g-1ubuntu4.19" }, { "binary_name": "openssl-dbgsym", "binary_version": "1.0.2g-1ubuntu4.19" } ], "availability": "No subscription required" }
{ "ubuntu_priority": "high", "binaries": [ { "binary_name": "libcrypto1.1-udeb", "binary_version": "1.1.1-1ubuntu2.1~18.04.9" }, { "binary_name": "libssl-dev", "binary_version": "1.1.1-1ubuntu2.1~18.04.9" }, { "binary_name": "libssl-doc", "binary_version": "1.1.1-1ubuntu2.1~18.04.9" }, { "binary_name": "libssl1.1", "binary_version": "1.1.1-1ubuntu2.1~18.04.9" }, { "binary_name": "libssl1.1-dbgsym", "binary_version": "1.1.1-1ubuntu2.1~18.04.9" }, { "binary_name": "libssl1.1-udeb", "binary_version": "1.1.1-1ubuntu2.1~18.04.9" }, { "binary_name": "openssl", "binary_version": "1.1.1-1ubuntu2.1~18.04.9" }, { "binary_name": "openssl-dbgsym", "binary_version": "1.1.1-1ubuntu2.1~18.04.9" } ], "availability": "No subscription required" }
{ "ubuntu_priority": "high", "binaries": [ { "binary_name": "libcrypto1.0.0-udeb", "binary_version": "1.0.2n-1ubuntu5.6" }, { "binary_name": "libssl1.0-dev", "binary_version": "1.0.2n-1ubuntu5.6" }, { "binary_name": "libssl1.0.0", "binary_version": "1.0.2n-1ubuntu5.6" }, { "binary_name": "libssl1.0.0-dbgsym", "binary_version": "1.0.2n-1ubuntu5.6" }, { "binary_name": "libssl1.0.0-udeb", "binary_version": "1.0.2n-1ubuntu5.6" }, { "binary_name": "openssl1.0", "binary_version": "1.0.2n-1ubuntu5.6" }, { "binary_name": "openssl1.0-dbgsym", "binary_version": "1.0.2n-1ubuntu5.6" } ], "availability": "No subscription required" }
{ "ubuntu_priority": "high", "binaries": [ { "binary_name": "libecpg-compat3", "binary_version": "10.18-0ubuntu0.18.04.1" }, { "binary_name": "libecpg-compat3-dbgsym", "binary_version": "10.18-0ubuntu0.18.04.1" }, { "binary_name": "libecpg-dev", "binary_version": "10.18-0ubuntu0.18.04.1" }, { "binary_name": "libecpg-dev-dbgsym", "binary_version": "10.18-0ubuntu0.18.04.1" }, { "binary_name": "libecpg6", "binary_version": "10.18-0ubuntu0.18.04.1" }, { "binary_name": "libecpg6-dbgsym", "binary_version": "10.18-0ubuntu0.18.04.1" }, { "binary_name": "libpgtypes3", "binary_version": "10.18-0ubuntu0.18.04.1" }, { "binary_name": "libpgtypes3-dbgsym", "binary_version": "10.18-0ubuntu0.18.04.1" }, { "binary_name": "libpq-dev", "binary_version": "10.18-0ubuntu0.18.04.1" }, { "binary_name": "libpq5", "binary_version": "10.18-0ubuntu0.18.04.1" }, { "binary_name": "libpq5-dbgsym", "binary_version": "10.18-0ubuntu0.18.04.1" }, { "binary_name": "postgresql-10", "binary_version": "10.18-0ubuntu0.18.04.1" }, { "binary_name": "postgresql-10-dbgsym", "binary_version": "10.18-0ubuntu0.18.04.1" }, { "binary_name": "postgresql-client-10", "binary_version": "10.18-0ubuntu0.18.04.1" }, { "binary_name": "postgresql-client-10-dbgsym", "binary_version": "10.18-0ubuntu0.18.04.1" }, { "binary_name": "postgresql-doc-10", "binary_version": "10.18-0ubuntu0.18.04.1" }, { "binary_name": "postgresql-plperl-10", "binary_version": "10.18-0ubuntu0.18.04.1" }, { "binary_name": "postgresql-plperl-10-dbgsym", "binary_version": "10.18-0ubuntu0.18.04.1" }, { "binary_name": "postgresql-plpython-10", "binary_version": "10.18-0ubuntu0.18.04.1" }, { "binary_name": "postgresql-plpython-10-dbgsym", "binary_version": "10.18-0ubuntu0.18.04.1" }, { "binary_name": "postgresql-plpython3-10", "binary_version": "10.18-0ubuntu0.18.04.1" }, { "binary_name": "postgresql-plpython3-10-dbgsym", "binary_version": "10.18-0ubuntu0.18.04.1" }, { "binary_name": "postgresql-pltcl-10", "binary_version": "10.18-0ubuntu0.18.04.1" }, { "binary_name": "postgresql-pltcl-10-dbgsym", "binary_version": "10.18-0ubuntu0.18.04.1" }, { "binary_name": "postgresql-server-dev-10", "binary_version": "10.18-0ubuntu0.18.04.1" }, { "binary_name": "postgresql-server-dev-10-dbgsym", "binary_version": "10.18-0ubuntu0.18.04.1" } ], "availability": "No subscription required" }
{ "ubuntu_priority": "high", "binaries": [ { "binary_name": "libcrypto1.1-udeb", "binary_version": "1.1.1-1ubuntu2.fips.2.1~18.04.9.1" }, { "binary_name": "libssl-dev", "binary_version": "1.1.1-1ubuntu2.fips.2.1~18.04.9.1" }, { "binary_name": "libssl-doc", "binary_version": "1.1.1-1ubuntu2.fips.2.1~18.04.9.1" }, { "binary_name": "libssl1.1", "binary_version": "1.1.1-1ubuntu2.fips.2.1~18.04.9.1" }, { "binary_name": "libssl1.1-dbgsym", "binary_version": "1.1.1-1ubuntu2.fips.2.1~18.04.9.1" }, { "binary_name": "libssl1.1-hmac", "binary_version": "1.1.1-1ubuntu2.fips.2.1~18.04.9.1" }, { "binary_name": "libssl1.1-udeb", "binary_version": "1.1.1-1ubuntu2.fips.2.1~18.04.9.1" }, { "binary_name": "openssl", "binary_version": "1.1.1-1ubuntu2.fips.2.1~18.04.9.1" }, { "binary_name": "openssl-dbgsym", "binary_version": "1.1.1-1ubuntu2.fips.2.1~18.04.9.1" } ], "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro" }
{ "ubuntu_priority": "high", "binaries": [ { "binary_name": "libcrypto1.1-udeb", "binary_version": "1.1.1f-1ubuntu2.3" }, { "binary_name": "libssl-dev", "binary_version": "1.1.1f-1ubuntu2.3" }, { "binary_name": "libssl-doc", "binary_version": "1.1.1f-1ubuntu2.3" }, { "binary_name": "libssl1.1", "binary_version": "1.1.1f-1ubuntu2.3" }, { "binary_name": "libssl1.1-dbgsym", "binary_version": "1.1.1f-1ubuntu2.3" }, { "binary_name": "libssl1.1-udeb", "binary_version": "1.1.1f-1ubuntu2.3" }, { "binary_name": "openssl", "binary_version": "1.1.1f-1ubuntu2.3" }, { "binary_name": "openssl-dbgsym", "binary_version": "1.1.1f-1ubuntu2.3" } ], "availability": "No subscription required" }
{ "ubuntu_priority": "high", "binaries": [ { "binary_name": "libecpg-compat3", "binary_version": "12.8-0ubuntu0.20.04.1" }, { "binary_name": "libecpg-compat3-dbgsym", "binary_version": "12.8-0ubuntu0.20.04.1" }, { "binary_name": "libecpg-dev", "binary_version": "12.8-0ubuntu0.20.04.1" }, { "binary_name": "libecpg-dev-dbgsym", "binary_version": "12.8-0ubuntu0.20.04.1" }, { "binary_name": "libecpg6", "binary_version": "12.8-0ubuntu0.20.04.1" }, { "binary_name": "libecpg6-dbgsym", "binary_version": "12.8-0ubuntu0.20.04.1" }, { "binary_name": "libpgtypes3", "binary_version": "12.8-0ubuntu0.20.04.1" }, { "binary_name": "libpgtypes3-dbgsym", "binary_version": "12.8-0ubuntu0.20.04.1" }, { "binary_name": "libpq-dev", "binary_version": "12.8-0ubuntu0.20.04.1" }, { "binary_name": "libpq5", "binary_version": "12.8-0ubuntu0.20.04.1" }, { "binary_name": "libpq5-dbgsym", "binary_version": "12.8-0ubuntu0.20.04.1" }, { "binary_name": "postgresql-12", "binary_version": "12.8-0ubuntu0.20.04.1" }, { "binary_name": "postgresql-12-dbgsym", "binary_version": "12.8-0ubuntu0.20.04.1" }, { "binary_name": "postgresql-client-12", "binary_version": "12.8-0ubuntu0.20.04.1" }, { "binary_name": "postgresql-client-12-dbgsym", "binary_version": "12.8-0ubuntu0.20.04.1" }, { "binary_name": "postgresql-doc-12", "binary_version": "12.8-0ubuntu0.20.04.1" }, { "binary_name": "postgresql-plperl-12", "binary_version": "12.8-0ubuntu0.20.04.1" }, { "binary_name": "postgresql-plperl-12-dbgsym", "binary_version": "12.8-0ubuntu0.20.04.1" }, { "binary_name": "postgresql-plpython3-12", "binary_version": "12.8-0ubuntu0.20.04.1" }, { "binary_name": "postgresql-plpython3-12-dbgsym", "binary_version": "12.8-0ubuntu0.20.04.1" }, { "binary_name": "postgresql-pltcl-12", "binary_version": "12.8-0ubuntu0.20.04.1" }, { "binary_name": "postgresql-pltcl-12-dbgsym", "binary_version": "12.8-0ubuntu0.20.04.1" }, { "binary_name": "postgresql-server-dev-12", "binary_version": "12.8-0ubuntu0.20.04.1" } ], "availability": "No subscription required" }
{ "ubuntu_priority": "high", "binaries": [ { "binary_name": "libcrypto1.1-udeb", "binary_version": "1.1.1f-1ubuntu2.fips.7" }, { "binary_name": "libssl-dev", "binary_version": "1.1.1f-1ubuntu2.fips.7" }, { "binary_name": "libssl-doc", "binary_version": "1.1.1f-1ubuntu2.fips.7" }, { "binary_name": "libssl1.1", "binary_version": "1.1.1f-1ubuntu2.fips.7" }, { "binary_name": "libssl1.1-dbgsym", "binary_version": "1.1.1f-1ubuntu2.fips.7" }, { "binary_name": "libssl1.1-hmac", "binary_version": "1.1.1f-1ubuntu2.fips.7" }, { "binary_name": "libssl1.1-udeb", "binary_version": "1.1.1f-1ubuntu2.fips.7" }, { "binary_name": "openssl", "binary_version": "1.1.1f-1ubuntu2.fips.7" }, { "binary_name": "openssl-dbgsym", "binary_version": "1.1.1f-1ubuntu2.fips.7" } ], "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro" }
{ "ubuntu_priority": "high", "binaries": [ { "binary_name": "libcrypto1.1-udeb", "binary_version": "1.1.1f-1ubuntu2.fips.2.8" }, { "binary_name": "libssl-dev", "binary_version": "1.1.1f-1ubuntu2.fips.2.8" }, { "binary_name": "libssl-doc", "binary_version": "1.1.1f-1ubuntu2.fips.2.8" }, { "binary_name": "libssl1.1", "binary_version": "1.1.1f-1ubuntu2.fips.2.8" }, { "binary_name": "libssl1.1-dbgsym", "binary_version": "1.1.1f-1ubuntu2.fips.2.8" }, { "binary_name": "libssl1.1-hmac", "binary_version": "1.1.1f-1ubuntu2.fips.2.8" }, { "binary_name": "libssl1.1-udeb", "binary_version": "1.1.1f-1ubuntu2.fips.2.8" }, { "binary_name": "openssl", "binary_version": "1.1.1f-1ubuntu2.fips.2.8" }, { "binary_name": "openssl-dbgsym", "binary_version": "1.1.1f-1ubuntu2.fips.2.8" } ], "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro" }
{ "ubuntu_priority": "high", "binaries": [ { "binary_name": "libnode-dev", "binary_version": "12.22.9~dfsg-1ubuntu3" }, { "binary_name": "libnode72", "binary_version": "12.22.9~dfsg-1ubuntu3" }, { "binary_name": "libnode72-dbgsym", "binary_version": "12.22.9~dfsg-1ubuntu3" }, { "binary_name": "nodejs", "binary_version": "12.22.9~dfsg-1ubuntu3" }, { "binary_name": "nodejs-dbgsym", "binary_version": "12.22.9~dfsg-1ubuntu3" }, { "binary_name": "nodejs-doc", "binary_version": "12.22.9~dfsg-1ubuntu3" } ], "availability": "No subscription required" }