The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrectly when both GENERAL_NAMEs contain an EDIPARTYNAME. A NULL pointer dereference and a crash may occur leading to a possible denial of service attack. OpenSSL itself uses the GENERAL_NAME_cmp function for two purposes: 1) Comparing CRL distribution point names between an available CRL and a CRL distribution point embedded in an X509 certificate 2) When verifying that a timestamp response token signer matches the timestamp authority name (exposed via the API functions TS_RESP_verify_response and TS_RESP_verify_token) If an attacker can control both items being compared then that attacker could trigger a crash. For example if the attacker can trick a client or server into checking a malicious certificate against a malicious CRL then this may occur. Note that some applications automatically download CRLs based on a URL embedded in a certificate. This checking happens prior to the signatures on the certificate and CRL being verified. OpenSSL's s_server, s_client and verify tools have support for the "-crl_download" option which implements automatic CRL downloading and this attack has been demonstrated to work against those tools. Note that an unrelated bug means that affected versions of OpenSSL cannot parse or construct correct encodings of EDIPARTYNAME. However it is possible to construct a malformed EDIPARTYNAME that OpenSSL's parser will accept and hence trigger this attack. All OpenSSL 1.1.1 and 1.0.2 versions are affected by this issue. Other OpenSSL releases are out of support and have not been checked. Fixed in OpenSSL 1.1.1i (Affected 1.1.1-1.1.1h). Fixed in OpenSSL 1.0.2x (Affected 1.0.2-1.0.2w).
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade openssl-perlUpgrade opensslUpgrade openssl-develUpgrade openssl-libs | May 4, 2022 | Dec 8, 2020 |
| Alpine Linux | — | Upgrade opensslUpgrade libresslUpgrade openssl3Upgrade openssl1.1-compat | Jan 5, 2021 | Dec 8, 2020 |
| Amazon Linux Ami 2 | — | Upgrade openssl11-libsUpgrade openssl11-staticUpgrade edk2-debuginfoUpgrade edk2-tools-pythonUpgrade openssl-develUpgrade edk2-aarch64Upgrade openssl-staticUpgrade edk2-toolsUpgrade openssl-perlUpgrade opensslUpgrade openssl-debuginfoUpgrade openssl11-develUpgrade openssl11-debuginfoUpgrade openssl11Upgrade openssl-libsUpgrade edk2-tools-docUpgrade edk2-ovmf | Dec 10, 2020 | Dec 8, 2020 |
| Amazon_linux | — | Upgrade openssl | Dec 10, 2020 | Dec 8, 2020 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Dec 8, 2020 |
| Centos_linux | — | Upgrade openssl-perlUpgrade openssl-debuginfoUpgrade openssl-libs-debuginfoUpgrade openssl-libsUpgrade opensslUpgrade openssl-debugsourceUpgrade openssl-develUpgrade openssl-static | Dec 21, 2020 | Dec 8, 2020 |
| Debian | — | Upgrade openssl | Dec 10, 2020 | Dec 8, 2020 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Jan 14, 2021 |
| Freebsd | — | Upgrade FreeBSDUpgrade opensslUpgrade nodeUpgrade mariadb105-serverUpgrade mariadb103-serverUpgrade node14Upgrade node10Upgrade node12Upgrade mysql56-serverUpgrade mysql80-serverUpgrade mariadb104-serverUpgrade mysql57-server | Apr 20, 2021 | Dec 8, 2020 |
| Gentoo Linux | — | Upgrade dev-libs/openssl. | Dec 29, 2020 | Dec 8, 2020 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | Dec 9, 2020 | Dec 8, 2020 |
| Huawei Euleros 2_0_sp2 | — | Upgrade openssl110f-libsUpgrade openssl110f-develUpgrade openssl110f | Feb 22, 2021 | Dec 8, 2020 |
| Huawei Euleros 2_0_sp3 | — | Upgrade openssl-libsUpgrade openssl-develUpgrade openssl | Jan 20, 2021 | Dec 8, 2020 |
| Huawei Euleros 2_0_sp5 | — | Upgrade openssl111d-develUpgrade openssl111dUpgrade openssl111d-staticUpgrade openssl111d-libs | Mar 24, 2021 | Dec 8, 2020 |
| Huawei Euleros 2_0_sp8 | — | Upgrade openssl-develUpgrade openssl-libsUpgrade opensslUpgrade openssl-perl | Feb 2, 2021 | Dec 8, 2020 |
| Huawei Euleros 2_0_sp9 | — | Upgrade opensslUpgrade openssl-libsUpgrade openssl-perl | Jan 5, 2021 | Dec 8, 2020 |
| Ibm Aix | — | Apply the fix or workaround for openssl_advisory32 | Feb 2, 2021 | Dec 8, 2020 |
| Microsoft Visual_studio | — | Update Microsoft Visual Studio 2019 to the latest version in the LTSC 16.7 version stream, or upgrade to a newer supported version of Visual Studio 2019.Update Microsoft Visual Studio 2017 to the latest version in the LTSC 15.9 version stream, or upgrade to a newer supported version of Visual Studio 2017.Update Microsoft Visual Studio 2019 to the latest version in the LTSC 16.11 version stream, or upgrade to a newer supported version of Visual Studio 2019.Update Microsoft Visual Studio 2019 to the latest version in the LTSC 16.9 version stream, or upgrade to a newer supported version of Visual Studio 2019.Update Microsoft Visual Studio 2019 to the latest version in the LTSC 16.4 version stream, or upgrade to a newer supported version of Visual Studio 2019. | Jun 25, 2025 | Oct 12, 2021 |
| Nutanix Ahv | — | Upgrade Nutanix AHV to the latest version | Jun 5, 2026 | Aug 24, 2022 |
| Oracle Mysql | — | Upgrade to MySQL version 5.7.33Upgrade to MySQL version 8.0.23 | Apr 8, 2021 | Dec 8, 2020 |
| Oracle Solaris | — | Upgrade runtime/nodejs/nodejs-12 to version 12.21.0-11.4.32.0.1.88.2 on Solaris 11.4Upgrade library/security/openssl to version 1.0.2.26-0.175.3.36.0.27.0 on Solaris 11.3Upgrade library/security/openssl to version 1.0.2.24-11.4.30.0.1.88.0 on Solaris 11.4Upgrade library/security/openssl/openssl-fips-140 to version 2.0.15-0.175.3.36.0.27.0 on Solaris 11.3Upgrade runtime/nodejs to version 12.21.0-11.4.32.0.1.88.2 on Solaris 11.4Upgrade library/security/openssl-11 to version 1.1.1.9-11.4.30.0.1.88.0 on Solaris 11.4Upgrade library/security/openssl/openssl-fips-140 to version 2.0.15-11.4.30.0.1.88.0 on Solaris 11.4Upgrade runtime/nodejs/nodejs-10 to version 10.22.1-11.4.32.0.1.88.2 on Solaris 11.4 | Feb 17, 2021 | Dec 8, 2020 |
| Oracle_linux | — | Upgrade openssl-libsUpgrade opensslUpgrade openssl-perlUpgrade openssl-staticUpgrade openssl-devel | Dec 17, 2020 | Dec 8, 2020 |
| Pulse Secure Pulse Connect Secure | — | Update Pulse Connect Secure to version 9.1R12 | May 12, 2021 | Dec 8, 2020 |
| Redhat Openshift | — | Upgrade redhat-coreos | Mar 12, 2021 | Dec 8, 2020 |
| Redhat_linux | — | Upgrade openssl-debuginfoUpgrade openssl-develUpgrade openssl-debugsourceUpgrade openssl-libsUpgrade opensslUpgrade openssl-libs-debuginfoUpgrade openssl-perlUpgrade openssl-staticNo solution exists | Dec 16, 2020 | Dec 8, 2020 |
| Suse | — | Upgrade libopenssl1_0_0-hmacUpgrade nodejs12-develUpgrade libopenssl-1_0_0-develUpgrade libopenssl10Upgrade nodejs10-docsUpgrade nodejs12-docsUpgrade libopenssl-1_1-devel-32bitUpgrade libopenssl-1_1-develUpgrade npm10Upgrade openssl-1_0_0-cavsUpgrade libopenssl1_0_0-steamUpgrade libopenssl1_0_0-32bitUpgrade libopenssl1_0_0-hmac-32bitUpgrade libopenssl1_0_0Upgrade opensslUpgrade libopenssl-1_0_0-devel-32bitUpgrade libopenssl-develUpgrade libopenssl3Upgrade nodejs10-develUpgrade npm12Upgrade openssl-1_1-docUpgrade openssl-docUpgrade libopenssl1_1-32bitUpgrade nodejs12Upgrade openssl-1_0_0-docUpgrade openssl-1_0_0Upgrade openssl1-docUpgrade libopenssl1_1Upgrade libopenssl1_0_0-steam-32bitUpgrade openssl-3Upgrade libopenssl1_1-hmac-32bitUpgrade nodejs10Upgrade openssl-1_1Upgrade openssl1Upgrade libopenssl-3-develUpgrade libopenssl1_0_0-x86Upgrade libopenssl1_1-hmacUpgrade libopenssl1-devel | Dec 12, 2020 | Dec 8, 2020 |
| Ubuntu | — | Upgrade libssl1.0.0Upgrade libssl1.0.0 (Ubuntu Pro)Upgrade libssl1.1 | Dec 9, 2020 | Dec 8, 2020 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Dec 8, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub