The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrectly when both GENERAL_NAMEs contain an EDIPARTYNAME. A NULL pointer dereference and a crash may occur leading to a possible denial of service attack. OpenSSL itself uses the GENERAL_NAME_cmp function for two purposes: 1) Comparing CRL distribution point names between an available CRL and a CRL distribution point embedded in an X509 certificate 2) When verifying that a timestamp response token signer matches the timestamp authority name (exposed via the API functions TS_RESP_verify_response and TS_RESP_verify_token) If an attacker can control both items being compared then that attacker could trigger a crash. For example if the attacker can trick a client or server into checking a malicious certificate against a malicious CRL then this may occur. Note that some applications automatically download CRLs based on a URL embedded in a certificate. This checking happens prior to the signatures on the certificate and CRL being verified. OpenSSL's s_server, s_client and verify tools have support for the "-crl_download" option which implements automatic CRL downloading and this attack has been demonstrated to work against those tools. Note that an unrelated bug means that affected versions of OpenSSL cannot parse or construct correct encodings of EDIPARTYNAME. However it is possible to construct a malformed EDIPARTYNAME that OpenSSL's parser will accept and hence trigger this attack. All OpenSSL 1.1.1 and 1.0.2 versions are affected by this issue. Other OpenSSL releases are out of support and have not been checked. Fixed in OpenSSL 1.1.1i (Affected 1.1.1-1.1.1h). Fixed in OpenSSL 1.0.2x (Affected 1.0.2-1.0.2w).
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade opensslUpgrade openssl-perlUpgrade openssl-libsUpgrade openssl-devel | May 4, 2022 | Dec 8, 2020 |
| Alpine Linux | — | Upgrade opensslUpgrade libresslUpgrade openssl1.1-compatUpgrade openssl3 | Jan 5, 2021 | Dec 8, 2020 |
| Amazon Linux Ami 2 | — | Upgrade edk2-toolsUpgrade edk2-tools-pythonUpgrade openssl11-libsUpgrade edk2-aarch64Upgrade openssl-staticUpgrade openssl11-staticUpgrade edk2-debuginfoUpgrade openssl-develUpgrade openssl11-develUpgrade edk2-ovmfUpgrade opensslUpgrade openssl11-debuginfoUpgrade openssl-perlUpgrade openssl11Upgrade openssl-libsUpgrade edk2-tools-docUpgrade openssl-debuginfo | Dec 10, 2020 | Dec 8, 2020 |
| Amazon_linux | — | Upgrade openssl | Dec 10, 2020 | Dec 8, 2020 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Dec 8, 2020 |
| Centos_linux | — | Upgrade openssl-staticUpgrade openssl-debugsourceUpgrade openssl-develUpgrade openssl-perlUpgrade openssl-libs-debuginfoUpgrade openssl-debuginfoUpgrade opensslUpgrade openssl-libs | Dec 21, 2020 | Dec 8, 2020 |
| Debian | — | Upgrade openssl | Dec 10, 2020 | Dec 8, 2020 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Jan 14, 2021 |
| Freebsd | — | Upgrade opensslUpgrade node14Upgrade mariadb103-serverUpgrade node10Upgrade nodeUpgrade FreeBSDUpgrade mariadb105-serverUpgrade mysql80-serverUpgrade node12Upgrade mariadb104-serverUpgrade mysql57-serverUpgrade mysql56-server | Apr 20, 2021 | Dec 8, 2020 |
| Gentoo Linux | — | Upgrade dev-libs/openssl. | Dec 29, 2020 | Dec 8, 2020 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | Dec 9, 2020 | Dec 8, 2020 |
| Huawei Euleros 2_0_sp2 | — | Upgrade openssl110fUpgrade openssl110f-develUpgrade openssl110f-libs | Feb 22, 2021 | Dec 8, 2020 |
| Huawei Euleros 2_0_sp3 | — | Upgrade openssl-libsUpgrade openssl-develUpgrade openssl | Jan 20, 2021 | Dec 8, 2020 |
| Huawei Euleros 2_0_sp5 | — | Upgrade openssl111d-develUpgrade openssl111dUpgrade openssl111d-libsUpgrade openssl111d-static | Mar 24, 2021 | Dec 8, 2020 |
| Huawei Euleros 2_0_sp8 | — | Upgrade openssl-libsUpgrade openssl-develUpgrade opensslUpgrade openssl-perl | Feb 2, 2021 | Dec 8, 2020 |
| Huawei Euleros 2_0_sp9 | — | Upgrade openssl-perlUpgrade openssl-libsUpgrade openssl | Jan 5, 2021 | Dec 8, 2020 |
| Ibm Aix | — | Apply the fix or workaround for openssl_advisory32 | Feb 2, 2021 | Dec 8, 2020 |
| Microsoft Visual_studio | — | Update Microsoft Visual Studio 2019 to the latest version in the LTSC 16.11 version stream, or upgrade to a newer supported version of Visual Studio 2019.Update Microsoft Visual Studio 2017 to the latest version in the LTSC 15.9 version stream, or upgrade to a newer supported version of Visual Studio 2017.Update Microsoft Visual Studio 2019 to the latest version in the LTSC 16.7 version stream, or upgrade to a newer supported version of Visual Studio 2019.Update Microsoft Visual Studio 2019 to the latest version in the LTSC 16.9 version stream, or upgrade to a newer supported version of Visual Studio 2019.Update Microsoft Visual Studio 2019 to the latest version in the LTSC 16.4 version stream, or upgrade to a newer supported version of Visual Studio 2019. | Jun 25, 2025 | Oct 12, 2021 |
| Nutanix Ahv | — | Upgrade Nutanix AHV to the latest version | Jun 5, 2026 | Aug 24, 2022 |
| Oracle Mysql | — | Upgrade to MySQL version 8.0.23Upgrade to MySQL version 5.7.33 | Apr 8, 2021 | Dec 8, 2020 |
| Oracle Solaris | — | Upgrade runtime/nodejs/nodejs-12 to version 12.21.0-11.4.32.0.1.88.2 on Solaris 11.4Upgrade library/security/openssl to version 1.0.2.24-11.4.30.0.1.88.0 on Solaris 11.4Upgrade library/security/openssl to version 1.0.2.26-0.175.3.36.0.27.0 on Solaris 11.3Upgrade library/security/openssl/openssl-fips-140 to version 2.0.15-0.175.3.36.0.27.0 on Solaris 11.3Upgrade library/security/openssl-11 to version 1.1.1.9-11.4.30.0.1.88.0 on Solaris 11.4Upgrade runtime/nodejs/nodejs-10 to version 10.22.1-11.4.32.0.1.88.2 on Solaris 11.4Upgrade runtime/nodejs to version 12.21.0-11.4.32.0.1.88.2 on Solaris 11.4Upgrade library/security/openssl/openssl-fips-140 to version 2.0.15-11.4.30.0.1.88.0 on Solaris 11.4 | Feb 17, 2021 | Dec 8, 2020 |
| Oracle_linux | — | Upgrade opensslUpgrade openssl-perlUpgrade openssl-libsUpgrade openssl-develUpgrade openssl-static | Dec 17, 2020 | Dec 8, 2020 |
| Pulse Secure Pulse Connect Secure | — | Update Pulse Connect Secure to version 9.1R12 | May 12, 2021 | Dec 8, 2020 |
| Redhat Openshift | — | Upgrade redhat-coreos | Mar 12, 2021 | Dec 8, 2020 |
| Redhat_linux | — | Upgrade opensslUpgrade openssl-staticNo solution existsUpgrade openssl-libs-debuginfoUpgrade openssl-perlUpgrade openssl-develUpgrade openssl-debugsourceUpgrade openssl-debuginfoUpgrade openssl-libs | Dec 16, 2020 | Dec 8, 2020 |
| Suse | — | Upgrade openssl1Upgrade nodejs10Upgrade openssl-1_1Upgrade libopenssl-3-develUpgrade libopenssl1_1-hmacUpgrade libopenssl1_0_0-x86Upgrade openssl-1_0_0-docUpgrade libopenssl1_0_0-steam-32bitUpgrade openssl-1_0_0Upgrade openssl-3Upgrade libopenssl1_1Upgrade openssl1-docUpgrade libopenssl1_1-hmac-32bitUpgrade libopenssl1-develUpgrade libopenssl-1_0_0-devel-32bitUpgrade libopenssl-1_1-devel-32bitUpgrade openssl-docUpgrade npm10Upgrade libopenssl-1_1-develUpgrade nodejs12-docsUpgrade libopenssl1_0_0-32bitUpgrade nodejs12Upgrade nodejs10-develUpgrade libopenssl1_0_0Upgrade libopenssl3Upgrade npm12Upgrade libopenssl1_0_0-hmacUpgrade opensslUpgrade openssl-1_1-docUpgrade libopenssl1_1-32bitUpgrade libopenssl-develUpgrade nodejs12-develUpgrade libopenssl1_0_0-steamUpgrade libopenssl1_0_0-hmac-32bitUpgrade libopenssl-1_0_0-develUpgrade nodejs10-docsUpgrade libopenssl10Upgrade openssl-1_0_0-cavs | Dec 12, 2020 | Dec 8, 2020 |
| Ubuntu | — | Upgrade libssl1.1Upgrade libssl1.0.0Upgrade libssl1.0.0 (Ubuntu Pro) | Dec 9, 2020 | Dec 8, 2020 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Dec 8, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub