The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrectly when both GENERAL_NAMEs contain an EDIPARTYNAME. A NULL pointer dereference and a crash may occur leading to a possible denial of service attack. OpenSSL itself uses the GENERAL_NAME_cmp function for two purposes: 1) Comparing CRL distribution point names between an available CRL and a CRL distribution point embedded in an X509 certificate 2) When verifying that a timestamp response token signer matches the timestamp authority name (exposed via the API functions TS_RESP_verify_response and TS_RESP_verify_token) If an attacker can control both items being compared then that attacker could trigger a crash. For example if the attacker can trick a client or server into checking a malicious certificate against a malicious CRL then this may occur. Note that some applications automatically download CRLs based on a URL embedded in a certificate. This checking happens prior to the signatures on the certificate and CRL being verified. OpenSSL's s_server, s_client and verify tools have support for the "-crl_download" option which implements automatic CRL downloading and this attack has been demonstrated to work against those tools. Note that an unrelated bug means that affected versions of OpenSSL cannot parse or construct correct encodings of EDIPARTYNAME. However it is possible to construct a malformed EDIPARTYNAME that OpenSSL's parser will accept and hence trigger this attack. All OpenSSL 1.1.1 and 1.0.2 versions are affected by this issue. Other OpenSSL releases are out of support and have not been checked. Fixed in OpenSSL 1.1.1i (Affected 1.1.1-1.1.1h). Fixed in OpenSSL 1.0.2x (Affected 1.0.2-1.0.2w).
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade openssl-develUpgrade openssl-libsUpgrade opensslUpgrade openssl-perl | May 4, 2022 | Dec 8, 2020 |
| Alpine Linux | — | Upgrade openssl3Upgrade openssl1.1-compatUpgrade opensslUpgrade libressl | Jan 5, 2021 | Dec 8, 2020 |
| Amazon Linux Ami 2 | — | Upgrade openssl-develUpgrade edk2-debuginfoUpgrade edk2-aarch64Upgrade openssl11-staticUpgrade edk2-toolsUpgrade openssl11-libsUpgrade openssl-staticUpgrade edk2-tools-pythonUpgrade openssl11-debuginfoUpgrade opensslUpgrade openssl11Upgrade openssl-perlUpgrade openssl11-develUpgrade openssl-libsUpgrade openssl-debuginfoUpgrade edk2-ovmfUpgrade edk2-tools-doc | Dec 10, 2020 | Dec 8, 2020 |
| Amazon_linux | — | Upgrade openssl | Dec 10, 2020 | Dec 8, 2020 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Dec 8, 2020 |
| Centos_linux | — | Upgrade opensslUpgrade openssl-debuginfoUpgrade openssl-perlUpgrade openssl-libsUpgrade openssl-libs-debuginfoUpgrade openssl-staticUpgrade openssl-develUpgrade openssl-debugsource | Dec 21, 2020 | Dec 8, 2020 |
| Debian | — | Upgrade openssl | Dec 10, 2020 | Dec 8, 2020 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Jan 14, 2021 |
| Freebsd | — | Upgrade node12Upgrade mysql80-serverUpgrade mysql56-serverUpgrade mariadb104-serverUpgrade mysql57-serverUpgrade opensslUpgrade node14Upgrade FreeBSDUpgrade nodeUpgrade mariadb105-serverUpgrade mariadb103-serverUpgrade node10 | Apr 20, 2021 | Dec 8, 2020 |
| Gentoo Linux | — | Upgrade dev-libs/openssl. | Dec 29, 2020 | Dec 8, 2020 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | Dec 9, 2020 | Dec 8, 2020 |
| Huawei Euleros 2_0_sp2 | — | Upgrade openssl110f-libsUpgrade openssl110f-develUpgrade openssl110f | Feb 22, 2021 | Dec 8, 2020 |
| Huawei Euleros 2_0_sp3 | — | Upgrade opensslUpgrade openssl-develUpgrade openssl-libs | Jan 20, 2021 | Dec 8, 2020 |
| Huawei Euleros 2_0_sp5 | — | Upgrade openssl111d-develUpgrade openssl111dUpgrade openssl111d-libsUpgrade openssl111d-static | Mar 24, 2021 | Dec 8, 2020 |
| Huawei Euleros 2_0_sp8 | — | Upgrade opensslUpgrade openssl-perlUpgrade openssl-libsUpgrade openssl-devel | Feb 2, 2021 | Dec 8, 2020 |
| Huawei Euleros 2_0_sp9 | — | Upgrade opensslUpgrade openssl-libsUpgrade openssl-perl | Jan 5, 2021 | Dec 8, 2020 |
| Ibm Aix | — | Apply the fix or workaround for openssl_advisory32 | Feb 2, 2021 | Dec 8, 2020 |
| Microsoft Visual_studio | — | Update Microsoft Visual Studio 2019 to the latest version in the LTSC 16.4 version stream, or upgrade to a newer supported version of Visual Studio 2019.Update Microsoft Visual Studio 2019 to the latest version in the LTSC 16.11 version stream, or upgrade to a newer supported version of Visual Studio 2019.Update Microsoft Visual Studio 2017 to the latest version in the LTSC 15.9 version stream, or upgrade to a newer supported version of Visual Studio 2017.Update Microsoft Visual Studio 2019 to the latest version in the LTSC 16.9 version stream, or upgrade to a newer supported version of Visual Studio 2019.Update Microsoft Visual Studio 2019 to the latest version in the LTSC 16.7 version stream, or upgrade to a newer supported version of Visual Studio 2019. | Jun 25, 2025 | Oct 12, 2021 |
| Nutanix Ahv | — | Upgrade Nutanix AHV to the latest version | Jun 5, 2026 | Aug 24, 2022 |
| Oracle Mysql | — | Upgrade to MySQL version 8.0.23Upgrade to MySQL version 5.7.33 | Apr 8, 2021 | Dec 8, 2020 |
| Oracle Solaris | — | Upgrade runtime/nodejs/nodejs-12 to version 12.21.0-11.4.32.0.1.88.2 on Solaris 11.4Upgrade library/security/openssl to version 1.0.2.24-11.4.30.0.1.88.0 on Solaris 11.4Upgrade library/security/openssl to version 1.0.2.26-0.175.3.36.0.27.0 on Solaris 11.3Upgrade runtime/nodejs/nodejs-10 to version 10.22.1-11.4.32.0.1.88.2 on Solaris 11.4Upgrade runtime/nodejs to version 12.21.0-11.4.32.0.1.88.2 on Solaris 11.4Upgrade library/security/openssl/openssl-fips-140 to version 2.0.15-0.175.3.36.0.27.0 on Solaris 11.3Upgrade library/security/openssl-11 to version 1.1.1.9-11.4.30.0.1.88.0 on Solaris 11.4Upgrade library/security/openssl/openssl-fips-140 to version 2.0.15-11.4.30.0.1.88.0 on Solaris 11.4 | Feb 17, 2021 | Dec 8, 2020 |
| Oracle_linux | — | Upgrade opensslUpgrade openssl-libsUpgrade openssl-perlUpgrade openssl-staticUpgrade openssl-devel | Dec 17, 2020 | Dec 8, 2020 |
| Pulse Secure Pulse Connect Secure | — | Update Pulse Connect Secure to version 9.1R12 | May 12, 2021 | Dec 8, 2020 |
| Redhat Openshift | — | Upgrade redhat-coreos | Mar 12, 2021 | Dec 8, 2020 |
| Redhat_linux | — | Upgrade openssl-develUpgrade openssl-debugsourceUpgrade openssl-libsUpgrade openssl-debuginfoUpgrade openssl-libs-debuginfoNo solution existsUpgrade openssl-staticUpgrade opensslUpgrade openssl-perl | Dec 16, 2020 | Dec 8, 2020 |
| Suse | — | Upgrade openssl-3Upgrade libopenssl1_1-hmac-32bitUpgrade openssl1-docUpgrade libopenssl1_0_0-x86Upgrade libopenssl1_1-hmacUpgrade openssl-1_0_0Upgrade libopenssl1_1Upgrade libopenssl1-develUpgrade openssl1Upgrade openssl-1_0_0-docUpgrade libopenssl1_0_0-steam-32bitUpgrade openssl-1_1Upgrade nodejs10Upgrade libopenssl-3-develUpgrade libopenssl1_0_0-steamUpgrade npm12Upgrade nodejs10-develUpgrade libopenssl-develUpgrade nodejs12Upgrade libopenssl1_0_0Upgrade npm10Upgrade libopenssl-1_0_0-devel-32bitUpgrade libopenssl1_0_0-hmacUpgrade libopenssl-1_0_0-develUpgrade nodejs12-docsUpgrade nodejs10-docsUpgrade openssl-1_1-docUpgrade libopenssl1_0_0-hmac-32bitUpgrade libopenssl1_0_0-32bitUpgrade libopenssl1_1-32bitUpgrade opensslUpgrade libopenssl3Upgrade openssl-docUpgrade libopenssl-1_1-develUpgrade nodejs12-develUpgrade libopenssl-1_1-devel-32bitUpgrade openssl-1_0_0-cavsUpgrade libopenssl10 | Dec 12, 2020 | Dec 8, 2020 |
| Ubuntu | — | Upgrade libssl1.0.0Upgrade libssl1.0.0 (Ubuntu Pro)Upgrade libssl1.1 | Dec 9, 2020 | Dec 8, 2020 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Dec 8, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub