NULL pointer dereference in OpenSSL - CVE-2020-1971
Published: December 8, 2020 / Updated: October 2, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error. A remote attacker can trigger denial of service conditions via the API functions TS_RESP_verify_response and TS_RESP_verify_token). If an attacker can control both items being compared then that attacker could trigger a crash. For example if the attacker can trick a client or server into checking a malicious certificate against a malicious CRL then this may occur. Note that some applications automatically download CRLs based on a URL embedded in a certificate. This checking happens prior to the signatures on the certificate and CRL being verified. OpenSSL's s_server, s_client and verify tools have support for the "-crl_download" option which implements automatic CRL downloading and this attack has been demonstrated to work against those tools. Note that an unrelated bug means that affected versions of OpenSSL cannot parse or construct correct encodings of EDIPARTYNAME. However it is possible to construct a malformed EDIPARTYNAME that OpenSSL's parser will accept and hence trigger this attack.
Affected software
IBM Security Verify Bridge
Oracle Communications Session Router
Oracle Communications Subscriber-Aware Load Balancer
IBM Netcool Agile Service Manager
Ansible Automation Platform
IBM Cloud Transformation Advisor
Dell PowerPath Management Appliance
Oracle VM Server for x86
EasyApache
IBM Rational Build Forge
InfoSphere Master Data Management
Oracle HTTP Server
Enterprise Manager Base Platform
Red Hat Advanced Cluster Management for Kubernetes
IBM MaaS360 Cloud Extender Agent
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Aspera Orchestrator
Engineering Workflow Management
NetWorker
Arch Linux
Gentoo Linux
Amazon Linux AMI
Red Hat Enterprise Linux Server - Extended Life Cycle Support
Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems)
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Fedora
CentOS
Red Hat Enterprise Linux for IBM System z (Structure A)
Red Hat Enterprise Linux for Power 9
IBM AIX
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Oracle Solaris
FreeBSD
Ubuntu
Junos OS
openEuler
JD Edwards World Security
Oracle Enterprise Session Border Controller
Oracle Enterprise Communications Broker
APM Edge
Telemetry Dashboard
IBM Security Privileged Identity Manager
Oracle Business Intelligence Enterprise Edition
Liquidware
Citrix Workspace App
Webex App VDI
HP-UX OpenSSL
IBM MaaS360 Base Module
IBM MaaS360 Ceriticate Integration Module
PowerFlex rack
Data Computing Appliance (DCA)
Flex System Fabric EN4093/EN4093R 10Gb Scalable Switch
SmartFabric OS10
Oracle Communications Session Border Controller
BIG-IQ Centralized Management
Oracle API Gateway
Oracle Enterprise Manager Ops Center
Orion Platform
Juniper Junos Space
Oracle Communications Unified Session Manager
Tenable.sc
Oracle Communications Cloud Native Core Network Function Cloud Native Environment
jbcs-httpd24-openssl-pkcs11 (Red Hat package)
openssl (Debian package)
jbcs-httpd24-brotli (Red Hat package)
openssl (Alpine package)
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-nghttp2 (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
libressl (Alpine package)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
jbcs-httpd24-openssl-chil (Red Hat package)
openssl (Red Hat package)
libssl1.0.0 (Ubuntu package)
openssl-devel
openssl
openssl-debuginfo
openssl-debugsource
openssl-help
openssl-libs
openssl11
libssl1.1 (Ubuntu package)
shim-debuginfo
shim-debugsource
shim
Azure Active Directory Pod Identity for Kubernets
Cloud Pak for Security (CP4S)
Cloud Pak for Data
IBM VIOS
Quay
Red Hat OpenShift Serverless
OpenShift Virtualization
IBM Netezza Host Management
Red Hat Ceph Storage
Nessus Network Monitor
Traffix SDC
JD Edwards EnterpriseOne Tools
VMware Horizon Client
IBM DataPower Gateway
RecoverPoint for VMs
MySQL Server
LANTIME Operating System Firmware (LTOS)
BIG-IP
BIG-IP SSLO
BIG-IP DDHD
APM Clients
BIG-IP Analytics
BIG-IP APM
BIG-IP LTM
BIG-IP FPS
BIG-IP AFM
BIG-IP GTM
BIG-IP PEM
BIG-IP ASM
MySQL Workbench
Visual Studio
Engineering Lifecycle Management
PeopleSoft Enterprise PeopleTools
IBM Cognos Analytics
Node.js
BIG-IP DNS
BIG-IP Link Controller
BIG-IP AAM
IBM Flex System Fabric SI4093 GbFSIM 10Gb Scalable Switch
IBM Flex System EN2092 1Gb Ethernet Scalable Switch
IBM Flex System CN4093 10Gb Converged Scalable Switch
BIG-IP Advanced WAF
Cisco Jabber
Cisco Webex Meetings
SINEC INS
IBM MaaS360 VPN Module
IBM Aspera Faspex for Linux
IBM Aspera Faspex for Windows
RSA Authentication Manager
How to mitigate CVE-2020-1971
Tenable.sc - update to 5.17.0
jbcs-httpd24-openssl-pkcs11 (Red Hat package) - update to 0.4.10-18.jbcs.el7
APM Edge - update to 4.0
openssl (Debian package) - update to 1.1.1d-0+deb10u4
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
jbcs-httpd24-brotli (Red Hat package) - update to 1.0.6-40.jbcs.el7
IBM Netcool Agile Service Manager - update to 1.1.13
openssl (Alpine package) - update to 1.1.1i-r0
Ansible Automation Platform - update to 1.2.4
Azure Active Directory Pod Identity for Kubernets - update to 1.7.1
Cloud Pak for Security (CP4S) - update to 1.8.0.0
jbcs-httpd24-mod_http2 (Red Hat package) - update to 1.15.7-12.jbcs.el7
jbcs-httpd24-nghttp2 (Red Hat package) - update to 1.39.2-35.jbcs.el7
jbcs-httpd24-mod_md (Red Hat package) - update to 2.0.8-31.jbcs.el7
jbcs-httpd24-httpd (Red Hat package) - update to 2.4.37-66.jbcs.el7
jbcs-httpd24-mod_security (Red Hat package) - update to 2.9.2-58.GA.jbcs.el7
libressl (Alpine package) - update to 3.1.5-r0
Quay - update to 3.3.3
EasyApache - update to 4 20201-3-3
Nessus Network Monitor - update to 5.13.1
RecoverPoint for VMs - update to 5.3.3.1
MySQL Server - addressed in versions 5.7.33, 8.0.23
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
LANTIME Operating System Firmware (LTOS) - addressed in versions 6.24.027, 7.00.014
IBM Rational Build Forge - update to 8.0.0.24
MySQL Workbench - update to 8.0.23
JD Edwards EnterpriseOne Tools - update to 9.2.5.3
Node.js - addressed in versions 10.23.1, 12.20.1, 14.15.4
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
Junos OS - addressed in versions 18.4R2-S10, 19.2R1-S9, 19.2R3-S5, 19.3R3-S5, 19.4R3-S7, 20.1R3-S3, 20.2R3-S4, 20.3R3-S2, 20.4R3-S1, 21.1R3-S1, 21.2R2-S1, 21.2R3, 21.3R2, 21.4R1
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
Orion Platform - update to 2024.2
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
HP-UX OpenSSL - update to A.01.01.01l.001
jbcs-httpd24-openssl-chil (Red Hat package) - update to 1.0.0-3.jbcs.el7
openssl (Red Hat package) - addressed in versions 1.0.1e-52.el7_2, 1.0.1e-59.el6_10, 1.0.1e-61.el7_3, 1.0.2k-9.el7_4, 1.0.2k-17.el7_6, 1.0.2k-21.el7_9, 1.1.1c-3.el8_1, 1.1.1c-16.el8_2, 1.1.1g-12.el8_3, 1.1.1-9.el8_0
libssl1.0.0 (Ubuntu package) - addressed in versions 1.0.1f-1ubuntu2.27+esm2, 1.0.1-4ubuntu5.45, 1.0.2g-1ubuntu4.18, 1.0.2n-1ubuntu5.5
SINEC INS - update to 1.0.1.1
openssl-devel - update to 1.1.1f-3
openssl - update to 1.1.1f-3
openssl-debuginfo - update to 1.1.1f-3
openssl-debugsource - update to 1.1.1f-3
openssl-help - update to 1.1.1f-3
openssl-libs - update to 1.1.1f-3
openssl11 - update to 1.1.1g-2.el7
openssl - addressed in versions 1.1.1i-1.fc32, 1.1.1i-1.fc33
libssl1.1 (Ubuntu package) - addressed in versions 1.1.1f-1ubuntu2.19, 1.1.1f-1ubuntu4.1, 1.1.1-1ubuntu2.1~18.04.7
Red Hat OpenShift Serverless - update to 1.12.0
Red Hat Advanced Cluster Management for Kubernetes - update to 2.1.3
Cloud Pak for Data - addressed in versions 2.5 patch 7, 3.0.1 patch 7
OpenShift Virtualization - update to 2.5.3
IBM MaaS360 Base Module - update to 2.105.300.005
IBM MaaS360 VPN Module - update to 2.105.300.005
IBM MaaS360 Ceriticate Integration Module - update to 2.105.300.005
IBM MaaS360 Cloud Extender Agent - update to 2.105.300.005
PowerFlex rack - addressed in versions 3.3.9.2, 3.4.4.2, 3.5.4.2
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.0.0
IBM Aspera Orchestrator - update to 4.0.1.2b9681
Data Computing Appliance (DCA) - update to 4.3.0.0
IBM Aspera Faspex for Linux - update to 4.4.2
IBM Aspera Faspex for Windows - update to 4.4.2
IBM Netezza Host Management - update to 5.4.31.0
Engineering Workflow Management - addressed in versions 7.0.1 iFix022, 7.0.2 iFix023
Engineering Lifecycle Management - addressed in versions 7.0.1 iFix022, 7.0.2 iFix023
IBM Flex System Fabric SI4093 GbFSIM 10Gb Scalable Switch - update to 7.8.31.0
IBM Flex System EN2092 1Gb Ethernet Scalable Switch - update to 7.8.31.0
Flex System Fabric EN4093/EN4093R 10Gb Scalable Switch - update to 7.8.31.0
IBM Flex System CN4093 10Gb Converged Scalable Switch - update to 7.8.31.0
RSA Authentication Manager - update to 8.5 Patch 3
IBM DataPower Gateway - addressed in versions 10.0.1.4, 10.0.3.0, 2018.4.1.17
SmartFabric OS10 - update to 10.5.2.3
IBM Cognos Analytics - addressed in versions 11.1.7 Fix Pack 8, 11.2.4 FP3, 12.0.2
shim-debuginfo - update to 15-23
shim-debugsource - update to 15-23
shim - update to 15-23
NetWorker - update to 19.10.0.0
Juniper Junos Space - update to 21.2R1
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- NULL pointer dereference in OpenSSL
- NULL pointer dereference in openssl (Alpine package)
- Debian update for openssl
- Amazon Linux AMI update for openssl
- FreeBSD update for OpenSSL
- Arch Linux update for openssl
- Red Hat Enterprise Linux 8 update for openssl
- Red Hat Enterprise Linux 7 update for openssl
- Red Hat Enterprise Linux 8 update for openssl
- Red Hat Enterprise Linux 7.7 update for openssl
- NULL pointer dereference in libressl (Alpine package)
- Red Hat Enterprise Linux Server AUS 7.2 update for openssl
- Red Hat Enterprise Linux Server AUS 7.3 update for openssl
- Red Hat Enterprise Linux Server 7.4 update for openssl
- Multiple vulnerabilities in Tenable.sc
- CentOS 7 update for openssl
- Red Hat Enterprise Linux 7.6 update for openssl
- Gentoo update for OpenSSL
- Red Hat Enterprise Linux 8.1 update for openssl
- Node.js update for OpenSSL
- Red Hat Enterprise Linux 6 Extended Lifecycle Support update for openssl
- Multiple vulnerabilities in Red Hat Quay
- Multiple vulnerabilities in Azure Active Directory Pod Identity for Kubernetes
- Red Hat update for Red Hat Ceph Storage 4.2
- OpenSSL vulnerability in multiple F5 products
- Multiple vulnerabilities in Red Hat OpenShift Serverless
- Multiple vulnerabilities in MySQL Workbench
- Multiple vulnerabilities in Oracle Solaris
- IBM AIX update for OpenSSL
- IBM VIOS update for OpenSSL
- Red Hat JBoss Core Services update for Apache HTTP Server
- EasyApache 4 update for NodeJS
- Multiple vulnerabilities in MySQL Server
- NULL pointer dereference in Oracle Enterprise Session Border Controller
- NULL pointer dereference in Oracle Communications Unified Session Manager
- Multiple vulnerabilities in Oracle Enterprise Communications Broker
- Multiple vulnerabilities in Oracle Communications Subscriber-Aware Load Balancer
- Multiple vulnerabilities in Oracle Communications Session Router
- Multiple vulnerabilities in Oracle Communications Session Border Controller
- NULL pointer dereference in Oracle Enterprise Manager Ops Center
- Multiple vulnerabilities in Oracle API Gateway
- Multiple vulnerabilities in Oracle Business Intelligence Enterprise Edition
- Multiple vulnerabilities in PeopleSoft Enterprise PeopleTools
- Multiple vulnerabilities in JD Edwards World Security
- Multiple vulnerabilities in JD Edwards EnterpriseOne Tools
- Multiple vulnerabilities in Nessus Network Monitor
- Multiple vulnerabilities in Enterprise Manager Base Platform
- Multiple vulnerabilities in Junos Space
- NULL pointer dereference in Microsoft Visual Studio
- Multiple vulnerabilities in Oracle HTTP Server
- Multiple vulnerabilities in Hitachi Energy APM Edge
- Multiple vulnerabilities in Siemens SINEC INS
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Network Function Cloud Native Environment
- Multiple Vulnerabilities in IBM Netcool Agile Service Manager
- Ubuntu update for openssl
- Junos OS update for OpenSSL
- Multiple vulnerabilities in Oracle VM Server
- NULL pointer dereference in IBM InfoSphere Master Data Management
- Multiple vulnerabilities in IBM Cloud Pak for Security
- NULL pointer dereference in IBM Netezza Host Management
- Multiple vulnerabilities in IBM DataPower Gateway
- Multiple vulnerabilities in IBM Security Privileged Identity Manager
- Multiple vulnerabilities in IBM Watson Assistant for IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM MaaS360 Cloud Extender and Modules
- Multiple vulnerabilities in IBM Security Verify Bridge
- Multiple vulnerabilities in IBM Aspera Faspex
- Multiple vulnerabilities in Dell EMCRecoverPoint
- NULL pointer dereference in Dell EMC Networking OS10
- Multiple vulnerabilities in Dell PowerFlex rack
- NULL pointer dereference in Dell EMC PowerPath Management Appliance
- Multiple vulnerabilities in Dell EMC Data Computing Appliance (DCA)
- Red Hat Enterprise Linux 8.2 Extended Update Support update for openssl
- NULL pointer dereference in IBM Aspera Orchestrator
- Multiple vulnerabilities in Red Hat Ansible Automation Platform 1.2
- Multiple vulnerabilities in HPE HP-UX Using OpenSSL
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- NULL pointer dereference in IBM Engineering Workflow Management (EWM)
- NULL pointer dereference in IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM Rational Build Forge
- Multiple vulnerabilities in Dell Networker
- Multiple vulnerabilities in IBM Cognos Analytics
- openEuler update for shim
- openEuler update for openssl
- SolarWinds Platform update for third-party components
- Multiple vulnerabilities in Dell ThinOS
- Multiple vulnerabilities in OpenShift Virtualization 2.5
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.1
- Ubuntu update for openssl
- Fedora 33 update for openssl
- Fedora 32 update for openssl
- Fedora EPEL 7 update for openssl11
- RSA Authentication Manager update for third-party components
- Meinberg LANTIME firmware update for OpenSSL
- Multiple vulnerabilities in IBM Flex System switch firmware products