The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrectly when both GENERAL_NAMEs contain an EDIPARTYNAME. A NULL pointer dereference and a crash may occur leading to a possible denial of service attack. OpenSSL itself uses the GENERAL_NAME_cmp function for two purposes: 1) Comparing CRL distribution point names between an available CRL and a CRL distribution point embedded in an X509 certificate 2) When verifying that a timestamp response token signer matches the timestamp authority name (exposed via the API functions TS_RESP_verify_response and TS_RESP_verify_token) If an attacker can control both items being compared then that attacker could trigger a crash. For example if the attacker can trick a client or server into checking a malicious certificate against a malicious CRL then this may occur. Note that some applications automatically download CRLs based on a URL embedded in a certificate. This checking happens prior to the signatures on the certificate and CRL being verified. OpenSSL's s_server, s_client and verify tools have support for the "-crl_download" option which implements automatic CRL downloading and this attack has been demonstrated to work against those tools. Note that an unrelated bug means that affected versions of OpenSSL cannot parse or construct correct encodings of EDIPARTYNAME. However it is possible to construct a malformed EDIPARTYNAME that OpenSSL's parser will accept and hence trigger this attack. All OpenSSL 1.1.1 and 1.0.2 versions are affected by this issue. Other OpenSSL releases are out of support and have not been checked. Fixed in OpenSSL 1.1.1i (Affected 1.1.1-1.1.1h). Fixed in OpenSSL 1.0.2x (Affected 1.0.2-1.0.2w).
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade openssl-libsUpgrade openssl-develUpgrade opensslUpgrade openssl-perl | May 4, 2022 | Dec 8, 2020 |
| Alpine Linux | — | Upgrade openssl3Upgrade openssl1.1-compatUpgrade opensslUpgrade libressl | Jan 5, 2021 | Dec 8, 2020 |
| Amazon Linux Ami 2 | — | Upgrade openssl-debuginfoUpgrade edk2-ovmfUpgrade edk2-tools-docUpgrade openssl-perlUpgrade openssl11-develUpgrade openssl-libsUpgrade openssl11-debuginfoUpgrade opensslUpgrade openssl11Upgrade openssl-staticUpgrade edk2-tools-pythonUpgrade openssl-develUpgrade edk2-debuginfoUpgrade edk2-aarch64Upgrade openssl11-libsUpgrade openssl11-staticUpgrade edk2-tools | Dec 10, 2020 | Dec 8, 2020 |
| Amazon_linux | — | Upgrade openssl | Dec 10, 2020 | Dec 8, 2020 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Dec 8, 2020 |
| Centos_linux | — | Upgrade openssl-libsUpgrade openssl-perlUpgrade opensslUpgrade openssl-debuginfoUpgrade openssl-libs-debuginfoUpgrade openssl-staticUpgrade openssl-debugsourceUpgrade openssl-devel | Dec 21, 2020 | Dec 8, 2020 |
| Debian | — | Upgrade openssl | Dec 10, 2020 | Dec 8, 2020 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Jan 14, 2021 |
| Freebsd | — | Upgrade mariadb104-serverUpgrade mysql56-serverUpgrade node12Upgrade mysql80-serverUpgrade mysql57-serverUpgrade node14Upgrade nodeUpgrade mariadb105-serverUpgrade opensslUpgrade mariadb103-serverUpgrade FreeBSDUpgrade node10 | Apr 20, 2021 | Dec 8, 2020 |
| Gentoo Linux | — | Upgrade dev-libs/openssl. | Dec 29, 2020 | Dec 8, 2020 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | Dec 9, 2020 | Dec 8, 2020 |
| Huawei Euleros 2_0_sp2 | — | Upgrade openssl110f-libsUpgrade openssl110f-develUpgrade openssl110f | Feb 22, 2021 | Dec 8, 2020 |
| Huawei Euleros 2_0_sp3 | — | Upgrade opensslUpgrade openssl-develUpgrade openssl-libs | Jan 20, 2021 | Dec 8, 2020 |
| Huawei Euleros 2_0_sp5 | — | Upgrade openssl111d-staticUpgrade openssl111dUpgrade openssl111d-libsUpgrade openssl111d-devel | Mar 24, 2021 | Dec 8, 2020 |
| Huawei Euleros 2_0_sp8 | — | Upgrade opensslUpgrade openssl-perlUpgrade openssl-develUpgrade openssl-libs | Feb 2, 2021 | Dec 8, 2020 |
| Huawei Euleros 2_0_sp9 | — | Upgrade openssl-libsUpgrade openssl-perlUpgrade openssl | Jan 5, 2021 | Dec 8, 2020 |
| Ibm Aix | — | Apply the fix or workaround for openssl_advisory32 | Feb 2, 2021 | Dec 8, 2020 |
| Microsoft Visual_studio | — | Update Microsoft Visual Studio 2019 to the latest version in the LTSC 16.4 version stream, or upgrade to a newer supported version of Visual Studio 2019.Update Microsoft Visual Studio 2019 to the latest version in the LTSC 16.9 version stream, or upgrade to a newer supported version of Visual Studio 2019.Update Microsoft Visual Studio 2017 to the latest version in the LTSC 15.9 version stream, or upgrade to a newer supported version of Visual Studio 2017.Update Microsoft Visual Studio 2019 to the latest version in the LTSC 16.7 version stream, or upgrade to a newer supported version of Visual Studio 2019.Update Microsoft Visual Studio 2019 to the latest version in the LTSC 16.11 version stream, or upgrade to a newer supported version of Visual Studio 2019. | Jun 25, 2025 | Oct 12, 2021 |
| Nutanix Ahv | — | Upgrade Nutanix AHV to the latest version | Jun 5, 2026 | Aug 24, 2022 |
| Oracle Mysql | — | Upgrade to MySQL version 5.7.33Upgrade to MySQL version 8.0.23 | Apr 8, 2021 | Dec 8, 2020 |
| Oracle Solaris | — | Upgrade runtime/nodejs/nodejs-12 to version 12.21.0-11.4.32.0.1.88.2 on Solaris 11.4Upgrade library/security/openssl to version 1.0.2.24-11.4.30.0.1.88.0 on Solaris 11.4Upgrade library/security/openssl to version 1.0.2.26-0.175.3.36.0.27.0 on Solaris 11.3Upgrade library/security/openssl/openssl-fips-140 to version 2.0.15-11.4.30.0.1.88.0 on Solaris 11.4Upgrade runtime/nodejs/nodejs-10 to version 10.22.1-11.4.32.0.1.88.2 on Solaris 11.4Upgrade library/security/openssl/openssl-fips-140 to version 2.0.15-0.175.3.36.0.27.0 on Solaris 11.3Upgrade runtime/nodejs to version 12.21.0-11.4.32.0.1.88.2 on Solaris 11.4Upgrade library/security/openssl-11 to version 1.1.1.9-11.4.30.0.1.88.0 on Solaris 11.4 | Feb 17, 2021 | Dec 8, 2020 |
| Oracle_linux | — | Upgrade openssl-staticUpgrade openssl-develUpgrade openssl-libsUpgrade opensslUpgrade openssl-perl | Dec 17, 2020 | Dec 8, 2020 |
| Pulse Secure Pulse Connect Secure | — | Update Pulse Connect Secure to version 9.1R12 | May 12, 2021 | Dec 8, 2020 |
| Redhat Openshift | — | Upgrade redhat-coreos | Mar 12, 2021 | Dec 8, 2020 |
| Redhat_linux | — | Upgrade opensslNo solution existsUpgrade openssl-libs-debuginfoUpgrade openssl-perlUpgrade openssl-staticUpgrade openssl-develUpgrade openssl-debuginfoUpgrade openssl-debugsourceUpgrade openssl-libs | Dec 16, 2020 | Dec 8, 2020 |
| Suse | — | Upgrade nodejs10-docsUpgrade nodejs12-docsUpgrade libopenssl1_0_0-32bitUpgrade libopenssl-develUpgrade opensslUpgrade libopenssl1_0_0-steamUpgrade libopenssl-1_1-devel-32bitUpgrade libopenssl1_1-32bitUpgrade nodejs10-develUpgrade libopenssl1_0_0-hmac-32bitUpgrade nodejs12Upgrade libopenssl1_0_0-hmacUpgrade libopenssl-1_0_0-develUpgrade openssl-1_1-docUpgrade libopenssl1_0_0Upgrade libopenssl10Upgrade libopenssl-1_1-develUpgrade nodejs12-develUpgrade openssl-docUpgrade npm12Upgrade npm10Upgrade openssl-1_0_0-cavsUpgrade libopenssl3Upgrade libopenssl-1_0_0-devel-32bitUpgrade openssl-1_1Upgrade openssl1Upgrade libopenssl-3-develUpgrade libopenssl1_1-hmacUpgrade libopenssl1_0_0-x86Upgrade libopenssl1_1Upgrade openssl-3Upgrade libopenssl1_0_0-steam-32bitUpgrade openssl-1_0_0-docUpgrade nodejs10Upgrade openssl-1_0_0Upgrade libopenssl1-develUpgrade openssl1-docUpgrade libopenssl1_1-hmac-32bit | Dec 12, 2020 | Dec 8, 2020 |
| Ubuntu | — | Upgrade libssl1.0.0 (Ubuntu Pro)Upgrade libssl1.0.0Upgrade libssl1.1 | Dec 9, 2020 | Dec 8, 2020 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Dec 8, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub