The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrectly when both GENERAL_NAMEs contain an EDIPARTYNAME. A NULL pointer dereference and a crash may occur leading to a possible denial of service attack. OpenSSL itself uses the GENERAL_NAME_cmp function for two purposes: 1) Comparing CRL distribution point names between an available CRL and a CRL distribution point embedded in an X509 certificate 2) When verifying that a timestamp response token signer matches the timestamp authority name (exposed via the API functions TS_RESP_verify_response and TS_RESP_verify_token) If an attacker can control both items being compared then that attacker could trigger a crash. For example if the attacker can trick a client or server into checking a malicious certificate against a malicious CRL then this may occur. Note that some applications automatically download CRLs based on a URL embedded in a certificate. This checking happens prior to the signatures on the certificate and CRL being verified. OpenSSL's s_server, s_client and verify tools have support for the "-crl_download" option which implements automatic CRL downloading and this attack has been demonstrated to work against those tools. Note that an unrelated bug means that affected versions of OpenSSL cannot parse or construct correct encodings of EDIPARTYNAME. However it is possible to construct a malformed EDIPARTYNAME that OpenSSL's parser will accept and hence trigger this attack. All OpenSSL 1.1.1 and 1.0.2 versions are affected by this issue. Other OpenSSL releases are out of support and have not been checked. Fixed in OpenSSL 1.1.1i (Affected 1.1.1-1.1.1h). Fixed in OpenSSL 1.0.2x (Affected 1.0.2-1.0.2w).
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade openssl-perlUpgrade opensslUpgrade openssl-develUpgrade openssl-libs | May 4, 2022 | Dec 8, 2020 |
| Alpine Linux | — | Upgrade opensslUpgrade libresslUpgrade openssl3Upgrade openssl1.1-compat | Jan 5, 2021 | Dec 8, 2020 |
| Amazon Linux Ami 2 | — | Upgrade openssl11-debuginfoUpgrade opensslUpgrade openssl-perlUpgrade openssl11Upgrade openssl-libsUpgrade openssl-debuginfoUpgrade edk2-ovmfUpgrade edk2-tools-docUpgrade openssl11-develUpgrade edk2-tools-pythonUpgrade openssl-develUpgrade edk2-debuginfoUpgrade edk2-aarch64Upgrade openssl11-staticUpgrade edk2-toolsUpgrade openssl-staticUpgrade openssl11-libs | Dec 10, 2020 | Dec 8, 2020 |
| Amazon_linux | — | Upgrade openssl | Dec 10, 2020 | Dec 8, 2020 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Dec 8, 2020 |
| Centos_linux | — | Upgrade openssl-perlUpgrade openssl-libs-debuginfoUpgrade openssl-debuginfoUpgrade opensslUpgrade openssl-libsUpgrade openssl-staticUpgrade openssl-debugsourceUpgrade openssl-devel | Dec 21, 2020 | Dec 8, 2020 |
| Debian | — | Upgrade openssl | Dec 10, 2020 | Dec 8, 2020 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Jan 14, 2021 |
| Freebsd | — | Upgrade mariadb105-serverUpgrade opensslUpgrade nodeUpgrade mariadb103-serverUpgrade node10Upgrade FreeBSDUpgrade node14Upgrade mysql57-serverUpgrade mysql80-serverUpgrade node12Upgrade mysql56-serverUpgrade mariadb104-server | Apr 20, 2021 | Dec 8, 2020 |
| Gentoo Linux | — | Upgrade dev-libs/openssl. | Dec 29, 2020 | Dec 8, 2020 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | Dec 9, 2020 | Dec 8, 2020 |
| Huawei Euleros 2_0_sp2 | — | Upgrade openssl110f-develUpgrade openssl110f-libsUpgrade openssl110f | Feb 22, 2021 | Dec 8, 2020 |
| Huawei Euleros 2_0_sp3 | — | Upgrade openssl-develUpgrade openssl-libsUpgrade openssl | Jan 20, 2021 | Dec 8, 2020 |
| Huawei Euleros 2_0_sp5 | — | Upgrade openssl111d-develUpgrade openssl111d-libsUpgrade openssl111dUpgrade openssl111d-static | Mar 24, 2021 | Dec 8, 2020 |
| Huawei Euleros 2_0_sp8 | — | Upgrade openssl-perlUpgrade opensslUpgrade openssl-libsUpgrade openssl-devel | Feb 2, 2021 | Dec 8, 2020 |
| Huawei Euleros 2_0_sp9 | — | Upgrade opensslUpgrade openssl-perlUpgrade openssl-libs | Jan 5, 2021 | Dec 8, 2020 |
| Ibm Aix | — | Apply the fix or workaround for openssl_advisory32 | Feb 2, 2021 | Dec 8, 2020 |
| Microsoft Visual_studio | — | Update Microsoft Visual Studio 2019 to the latest version in the LTSC 16.7 version stream, or upgrade to a newer supported version of Visual Studio 2019.Update Microsoft Visual Studio 2019 to the latest version in the LTSC 16.9 version stream, or upgrade to a newer supported version of Visual Studio 2019.Update Microsoft Visual Studio 2019 to the latest version in the LTSC 16.11 version stream, or upgrade to a newer supported version of Visual Studio 2019.Update Microsoft Visual Studio 2017 to the latest version in the LTSC 15.9 version stream, or upgrade to a newer supported version of Visual Studio 2017.Update Microsoft Visual Studio 2019 to the latest version in the LTSC 16.4 version stream, or upgrade to a newer supported version of Visual Studio 2019. | Jun 25, 2025 | Oct 12, 2021 |
| Nutanix Ahv | — | Upgrade Nutanix AHV to the latest version | Jun 5, 2026 | Aug 24, 2022 |
| Oracle Mysql | — | Upgrade to MySQL version 8.0.23Upgrade to MySQL version 5.7.33 | Apr 8, 2021 | Dec 8, 2020 |
| Oracle Solaris | — | Upgrade runtime/nodejs/nodejs-12 to version 12.21.0-11.4.32.0.1.88.2 on Solaris 11.4Upgrade library/security/openssl to version 1.0.2.24-11.4.30.0.1.88.0 on Solaris 11.4Upgrade library/security/openssl to version 1.0.2.26-0.175.3.36.0.27.0 on Solaris 11.3Upgrade runtime/nodejs/nodejs-10 to version 10.22.1-11.4.32.0.1.88.2 on Solaris 11.4Upgrade library/security/openssl/openssl-fips-140 to version 2.0.15-11.4.30.0.1.88.0 on Solaris 11.4Upgrade library/security/openssl/openssl-fips-140 to version 2.0.15-0.175.3.36.0.27.0 on Solaris 11.3Upgrade runtime/nodejs to version 12.21.0-11.4.32.0.1.88.2 on Solaris 11.4Upgrade library/security/openssl-11 to version 1.1.1.9-11.4.30.0.1.88.0 on Solaris 11.4 | Feb 17, 2021 | Dec 8, 2020 |
| Oracle_linux | — | Upgrade openssl-staticUpgrade openssl-develUpgrade openssl-perlUpgrade openssl-libsUpgrade openssl | Dec 17, 2020 | Dec 8, 2020 |
| Pulse Secure Pulse Connect Secure | — | Update Pulse Connect Secure to version 9.1R12 | May 12, 2021 | Dec 8, 2020 |
| Redhat Openshift | — | Upgrade redhat-coreos | Mar 12, 2021 | Dec 8, 2020 |
| Redhat_linux | — | Upgrade openssl-libs-debuginfoNo solution existsUpgrade openssl-staticUpgrade openssl-perlUpgrade opensslUpgrade openssl-libsUpgrade openssl-develUpgrade openssl-debugsourceUpgrade openssl-debuginfo | Dec 16, 2020 | Dec 8, 2020 |
| Suse | — | Upgrade openssl-1_1Upgrade libopenssl-3-develUpgrade libopenssl1_1-hmacUpgrade libopenssl1_1-hmac-32bitUpgrade libopenssl1_0_0-x86Upgrade openssl1Upgrade libopenssl1-develUpgrade openssl-3Upgrade openssl1-docUpgrade openssl-1_0_0Upgrade libopenssl1_0_0-steam-32bitUpgrade openssl-1_0_0-docUpgrade nodejs10Upgrade libopenssl1_1Upgrade libopenssl1_0_0-hmac-32bitUpgrade openssl-docUpgrade npm12Upgrade libopenssl1_0_0-hmacUpgrade nodejs10-docsUpgrade nodejs12-docsUpgrade libopenssl1_0_0-steamUpgrade libopenssl-develUpgrade opensslUpgrade nodejs12-develUpgrade libopenssl-1_1-develUpgrade libopenssl-1_0_0-devel-32bitUpgrade libopenssl-1_1-devel-32bitUpgrade libopenssl3Upgrade libopenssl1_0_0Upgrade nodejs10-develUpgrade nodejs12Upgrade libopenssl1_1-32bitUpgrade openssl-1_1-docUpgrade openssl-1_0_0-cavsUpgrade libopenssl10Upgrade npm10Upgrade libopenssl-1_0_0-develUpgrade libopenssl1_0_0-32bit | Dec 12, 2020 | Dec 8, 2020 |
| Ubuntu | — | Upgrade libssl1.1Upgrade libssl1.0.0Upgrade libssl1.0.0 (Ubuntu Pro) | Dec 9, 2020 | Dec 8, 2020 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Dec 8, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub