Buffer overflow in OpenSSL - CVE-2021-3711
Published: August 24, 2021
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in EVP_PKEY_decrypt() function within implementation of the SM2 decryption. A remote attacker can send specially crafted SM2 content for decryption to trigger a buffer overflow by 62 bytes and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
PowerPath Windows
IBM Security Verify Gateway
cflinuxfs3
Astronomer with IBM
IBM Security Verify Information Queue
HP-UX OpenSSL
Db2 Rest
Dell Hybrid Client
DB2 on Cloud Pak for Data
DB2 Warehouse on Cloud Pak for Data
Watson Studio on Cloud Pak for Data
RecoverPoint Classic
MELSOFT iQ AppPortal
Nessus Network Monitor
JD Edwards EnterpriseOne Tools
IBM Watson Explorer Foundational Components
IBM Watson Explorer Deep Analytics Edition Foundational Components
Gentoo Linux
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 12
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Module for SUSE Manager Server
SUSE Manager Server
SUSE MicroOS
SUSE Linux Enterprise Micro
SUSE Manager Client Tools Beta for SLE Micro
SUSE Enterprise Storage
IBM i
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
HPE Helion Openstack
SUSE Manager Tools
SUSE Manager Client Tools Beta for SLE
FreeBSD
SUSE Linux Enterprise Server for the Raspberry Pi
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise High Performance Computing
openSUSE Leap
Ubuntu
openEuler
Brocade Fabric OS
JD Edwards World Security
openssl (Debian package)
firewalld-prometheus-config
dracut-saltboot
kiwi-desc-saltboot
golang-github-QubitProducts-exporter_exporter
prometheus-postgres_exporter
golang-github-prometheus-promu
prometheus-blackbox_exporter-debuginfo
prometheus-blackbox_exporter
golang-github-prometheus-alertmanager
system-user-prometheus
system-user-grafana
golang-github-lusitaniae-apache_exporter
golang-github-lusitaniae-apache_exporter-debuginfo
openssl-1_1-debuginfo
libopenssl1_1
libopenssl1_1-32bit
libopenssl1_1-debuginfo
libopenssl1_1-debuginfo-32bit
openssl-1_1
openssl-1_1-debugsource
libopenssl-1_1-devel-32bit
libopenssl-1_1-devel
libopenssl1_1-hmac
libopenssl1_1-32bit-debuginfo
libopenssl1_1-hmac-32bit
openssl-debuginfo
openssl-devel
openssl-libs
openssl-debugsource
openssl-help
openssl
dev-libs/openssl
libssl1.1 (Ubuntu package)
supportutils-plugin-salt
golang-github-prometheus-node_exporter
golang-github-boynux-squid_exporter
golang-github-boynux-squid_exporter-debuginfo
python2-hwdata
python3-hwdata
ansible
ansible-doc
golang-github-prometheus-prometheus
python3-mgr-virtualization-host
python3-mgr-virtualization-common
mgr-virtualization-host
spacewalk-oscap
python3-spacewalk-oscap
python3-mgr-push
mgr-push
suseRegisterInfo
python3-suseRegisterInfo
python3-spacewalk-koan
spacewalk-koan
python3-rhnlib
python3-mgr-cfg-client
python3-mgr-cfg-actions
python3-mgr-cfg
python3-mgr-cfg-management
mgr-cfg-management
mgr-cfg-client
mgr-cfg-actions
mgr-cfg
python3-mgr-osa-common
mgr-osad
python3-mgr-osad
spacecmd
python3-spacewalk-client-setup
spacewalk-client-tools
spacewalk-client-setup
spacewalk-check
python3-spacewalk-client-tools
python3-spacewalk-check
supportutils-plugin-susemanager-client
mgr-custom-info
spacewalk-remote-utils
python2-suseRegisterInfo
python2-uyuni-common-libs
python2-mgr-push
mgr-daemon
python2-rhnlib
python2-mgr-virtualization-host
python2-mgr-virtualization-common
python2-spacewalk-oscap
python2-spacewalk-koan
python2-mgr-cfg-management
python2-mgr-cfg-client
python2-mgr-cfg-actions
python2-mgr-cfg
python2-mgr-osad
python2-mgr-osa-common
python2-spacewalk-client-tools
python2-spacewalk-check
python2-spacewalk-client-setup
uyuni-proxy-systemd-services
python3-uyuni-common-libs
python3-pyvmomi
app-backup/tsm
grafana
grafana-debuginfo
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
EasyApache
IBM Tivoli Netcool System Service Monitors/Application Service Monitors
IBM Rational ClearQuest
Rational Application Developer
Autodesk Infraworks
Netcool Operations Insight
IBM Cloud Transformation Advisor
Steel Belted Radius Carrier Edition
PowerProtect Data Manager
RecoverPoint for VMs
MySQL Server
Oracle Essbase
Tenable.sc
Oracle Health Sciences InForm Publisher
Visual Studio
SINEC INS
Inspiron 3521
Wyse 5470
Wyse 5070
PowerScale OneFS
IBM Security Verify Access
IBM Cognos Analytics
How to mitigate CVE-2021-3711
MELSOFT iQ AppPortal - update to 1.29F
cflinuxfs3 - update to 0.253.0
Astronomer with IBM - update to 0.37.1
openssl (Debian package) - addressed in versions 1.1.1k-1+deb11u1, 1.1.1d-0+deb10u7
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - addressed in versions 4.5.3, 4.8.0
EasyApache - update to 4 2021-9-1
Nessus Network Monitor - addressed in versions 6.0.0, 6.0.1
RecoverPoint for VMs - update to 5.3.3.1
MySQL Server - update to 8.0.27
JD Edwards EnterpriseOne Tools - update to 9.2.6.3
IBM Security Verify Information Queue - update to 10.0.3
IBM Watson Explorer Foundational Components - update to 11.0.2.11
IBM Watson Explorer Deep Analytics Edition Foundational Components - update to 12.0.3.7
Oracle Essbase - addressed in versions 11.1.2.4.047, 21.3
Autodesk Infraworks - addressed in versions 2020.2 Hotfix 7, 2021.2 Hotfix 7, 2022.1.5 Hotfix 5, 2023.0.1 Hotfix 1
HP-UX OpenSSL - update to A.01.01.01l.001
firewalld-prometheus-config - update to 0.1-159000.6.33.1
dracut-saltboot - update to 0.1.1681904360.84ef141-159000.3.30.1
kiwi-desc-saltboot - update to 0.1.1687520761.cefb248-4.15.2
golang-github-QubitProducts-exporter_exporter - addressed in versions 0.4.0-1.6.1, 0.4.0-4.6.2, 0.4.0-159000.4.6.1
prometheus-postgres_exporter - addressed in versions 0.10.0-1.8.2, 0.10.0-150000.1.3.1, 0.10.1-3.6.4, 0.10.1-159000.3.6.1
golang-github-prometheus-promu - update to 0.14.0-4.12.2
prometheus-blackbox_exporter-debuginfo - addressed in versions 0.19.0-1.8.2, 0.24.0-3.6.3
prometheus-blackbox_exporter - addressed in versions 0.19.0-1.8.2, 0.24.0-3.6.3, 0.24.0-159000.3.6.1
golang-github-prometheus-alertmanager - addressed in versions 0.23.0-1.12.3, 0.26.0-4.12.4
system-user-prometheus - update to 1.0.0-3.7.2
system-user-grafana - update to 1.0.0-3.7.2
golang-github-lusitaniae-apache_exporter - addressed in versions 1.0.0-4.12.4, 1.0.0-159000.4.12.1
Db2 Rest - update to 1.0.0.304
golang-github-lusitaniae-apache_exporter-debuginfo - update to 1.0.0-159000.4.12.1
SINEC INS - update to 1.0.1.1
Dell Hybrid Client - addressed in versions 1.1.01, 1.2.1-14
openssl-1_1-debuginfo - addressed in versions 1.1.1d-2.36.2, 1.1.1d-11.27.1
libopenssl1_1 - addressed in versions 1.1.1d-2.36.2, 1.1.1d-11.27.1
libopenssl1_1-32bit - addressed in versions 1.1.1d-2.36.2, 1.1.1d-11.27.1
libopenssl1_1-debuginfo - addressed in versions 1.1.1d-2.36.2, 1.1.1d-11.27.1
libopenssl1_1-debuginfo-32bit - update to 1.1.1d-2.36.2
openssl-1_1 - addressed in versions 1.1.1d-2.36.2, 1.1.1d-11.27.1
openssl-1_1-debugsource - addressed in versions 1.1.1d-2.36.2, 1.1.1d-11.27.1
libopenssl-1_1-devel-32bit - update to 1.1.1d-2.36.2
libopenssl-1_1-devel - addressed in versions 1.1.1d-2.36.2, 1.1.1d-11.27.1
libopenssl1_1-hmac - update to 1.1.1d-11.27.1
libopenssl1_1-32bit-debuginfo - update to 1.1.1d-11.27.1
libopenssl1_1-hmac-32bit - update to 1.1.1d-11.27.1
openssl-debuginfo - update to 1.1.1f-11
openssl-devel - update to 1.1.1f-11
openssl-libs - update to 1.1.1f-11
openssl-debugsource - update to 1.1.1f-11
openssl-help - update to 1.1.1f-11
openssl - update to 1.1.1f-11
dev-libs/openssl - update to 1.1.1q
libssl1.1 (Ubuntu package) - addressed in versions 1.1.1f-1ubuntu2.8, 1.1.1j-1ubuntu3.5, 1.1.1-1ubuntu2.1~18.04.13
supportutils-plugin-salt - addressed in versions 1.2.0-6.16.1, 1.2.2-9.9.2, 1.2.2-159000.5.9.1
golang-github-prometheus-node_exporter - addressed in versions 1.3.0-1.15.3, 1.5.0-4.15.4
golang-github-boynux-squid_exporter - addressed in versions 1.6-4.9.2, 1.6-159000.4.9.1
Netcool Operations Insight - update to 1.6.8
golang-github-boynux-squid_exporter-debuginfo - update to 1.6-159000.4.9.1
Inspiron 3521 - update to 1.9.0
python2-hwdata - addressed in versions 2.3.5-12.9.1, 2.3.5-15.12.2
python3-hwdata - update to 2.3.5-159000.5.13.1
ansible - update to 2.9.27-159000.3.9.1
ansible-doc - update to 2.9.27-159000.3.9.1
golang-github-prometheus-prometheus - addressed in versions 2.45.0-4.33.3, 2.45.0-159000.6.33.1
IBM Cloud Transformation Advisor - update to 3.10.0
python3-mgr-virtualization-host - update to 4.2.4-150000.1.26.1
python3-mgr-virtualization-common - update to 4.2.4-150000.1.26.1
mgr-virtualization-host - addressed in versions 4.2.4-150000.1.26.1, 4.3.5-1.29.3
spacewalk-oscap - addressed in versions 4.2.4-150000.3.18.1, 4.3.5-19.27.1
python3-spacewalk-oscap - update to 4.2.4-150000.3.18.1
python3-mgr-push - addressed in versions 4.2.5-150000.1.18.2, 5.0.1-159000.4.21.1
mgr-push - addressed in versions 4.2.5-150000.1.18.2, 4.3.4-1.21.4, 5.0.1-4.21.4, 5.0.1-159000.4.21.1
suseRegisterInfo - addressed in versions 4.2.6-150000.3.21.1, 4.3.3-25.27.3
python3-suseRegisterInfo - update to 4.2.6-150000.3.21.1
python3-spacewalk-koan - update to 4.2.6-150000.3.27.1
spacewalk-koan - addressed in versions 4.2.6-150000.3.27.1, 4.3.5-24.33.3
python3-rhnlib - addressed in versions 4.2.6-150000.3.34.1, 5.0.1-159000.6.30.1
python3-mgr-cfg-client - update to 4.2.8-150000.1.24.1
python3-mgr-cfg-actions - update to 4.2.8-150000.1.24.1
python3-mgr-cfg - update to 4.2.8-150000.1.24.1
python3-mgr-cfg-management - update to 4.2.8-150000.1.24.1
mgr-cfg-management - addressed in versions 4.2.8-150000.1.24.1, 4.3.6-1.27.4
mgr-cfg-client - addressed in versions 4.2.8-150000.1.24.1, 4.3.6-1.27.4
mgr-cfg-actions - addressed in versions 4.2.8-150000.1.24.1, 4.3.6-1.27.4
mgr-cfg - addressed in versions 4.2.8-150000.1.24.1, 4.3.6-1.27.4
python3-mgr-osa-common - update to 4.2.8-150000.1.36.1
mgr-osad - addressed in versions 4.2.8-150000.1.36.1, 4.3.6-1.39.4
python3-mgr-osad - update to 4.2.8-150000.1.36.1
spacecmd - addressed in versions 4.2.16-150000.3.77.1, 4.3.11-38.103.3, 5.0.1-41.42.3, 5.0.1-159000.6.42.1
python3-spacewalk-client-setup - addressed in versions 4.2.18-150000.3.59.1, 5.0.1-159000.6.48.1
spacewalk-client-tools - addressed in versions 4.2.18-150000.3.59.1, 4.3.9-52.71.3, 5.0.1-159000.6.48.1
spacewalk-client-setup - addressed in versions 4.2.18-150000.3.59.1, 4.3.9-52.71.3, 5.0.1-159000.6.48.1
spacewalk-check - addressed in versions 4.2.18-150000.3.59.1, 4.3.9-52.71.3, 5.0.1-159000.6.48.1
python3-spacewalk-client-tools - addressed in versions 4.2.18-150000.3.59.1, 5.0.1-159000.6.48.1
python3-spacewalk-check - addressed in versions 4.2.18-150000.3.59.1, 5.0.1-159000.6.48.1
supportutils-plugin-susemanager-client - addressed in versions 4.3.2-6.24.1, 5.0.1-9.15.2, 5.0.1-159000.6.15.1
mgr-custom-info - update to 4.3.3-1.18.1
spacewalk-remote-utils - update to 4.3.3-24.24.3
python2-suseRegisterInfo - update to 4.3.3-25.27.3
python2-uyuni-common-libs - addressed in versions 4.3.4-1.21.3, 5.0.1-3.33.3
python2-mgr-push - addressed in versions 4.3.4-1.21.4, 5.0.1-4.21.4
mgr-daemon - update to 4.3.4-1.32.3
python2-rhnlib - addressed in versions 4.3.4-21.43.3, 5.0.1-24.30.3
python2-mgr-virtualization-host - update to 4.3.5-1.29.3
python2-mgr-virtualization-common - update to 4.3.5-1.29.3
python2-spacewalk-oscap - update to 4.3.5-19.27.1
python2-spacewalk-koan - update to 4.3.5-24.33.3
python2-mgr-cfg-management - update to 4.3.6-1.27.4
python2-mgr-cfg-client - update to 4.3.6-1.27.4
python2-mgr-cfg-actions - update to 4.3.6-1.27.4
python2-mgr-cfg - update to 4.3.6-1.27.4
python2-mgr-osad - update to 4.3.6-1.39.4
python2-mgr-osa-common - update to 4.3.6-1.39.4
python2-spacewalk-client-tools - update to 4.3.9-52.71.3
python2-spacewalk-check - update to 4.3.9-52.71.3
python2-spacewalk-client-setup - update to 4.3.9-52.71.3
DB2 on Cloud Pak for Data - update to 4.8.2
DB2 Warehouse on Cloud Pak for Data - update to 4.8.2
Watson Studio on Cloud Pak for Data - addressed in versions 4.8.7, 5.1.0
uyuni-proxy-systemd-services - update to 5.0.1-159000.3.9.1
python3-uyuni-common-libs - update to 5.0.1-159000.3.33.1
RecoverPoint Classic - update to 5.1 SP4 P5
python3-pyvmomi - update to 6.7.3-159000.3.6.1
app-backup/tsm - update to 8.1.13.3
grafana - addressed in versions 8.3.5-1.30.3, 8.3.5-150000.1.30.1, 8.5.13-150100.3.12.1, 9.5.8-4.21.2, 9.5.8-159000.4.24.1
grafana-debuginfo - addressed in versions 8.3.5-150000.1.30.1, 8.5.13-150100.3.12.1, 9.5.8-159000.4.24.1
Steel Belted Radius Carrier Edition - update to 8.6.0R16
Brocade Fabric OS - addressed in versions 9.0.1e, 9.1.0
IBM Security Verify Access - update to 10.0.7.0
Wyse 5470 - update to 10.04.06.01.22.00
Wyse 5070 - update to 10.04.06.01.22.00
IBM Cognos Analytics - addressed in versions 11.1.7.6, 11.2.3
PowerScale OneFS - update to 12.0
PowerProtect Data Manager - update to 19.19.0-15
External References
Related Security Bulletins
- Multiple vulnerabilities in OpenSSL
- Multiple vulnerabilities in Cloud Foundry Foundation cflinuxfs3
- FreeBSD update for OpenSSL
- Debian update for openssl
- Multiple vulnerabilities in cPanel EasyApache
- Multiple vulnerabilities in Dell PowerPath Windows
- Tenable.sc update for OpenSSL
- Multiple vulnerabilities in MySQL Server
- Remote code execution in Microsoft Visual Studio
- Multiple vulnerabilities in IBM Rational ClearQuest
- Multiple vulnerabilities in IBM Tivoli Netcool System Service Monitors/Application Service Monitors
- Nessus Network Monitor update for OpenSSL
- Multiple vulnerabilities in Oracle Essbase
- Multiple vulnerabilities in Siemens SINEC INS
- Buffer overflow in Oracle Health Sciences InForm Publisher
- Buffer overflow in JD Edwards World Security
- Multiple vulnerabilities in JD Edwards EnterpriseOne Tools
- Multiple vulnerabilities in Mitsubishi Electric MELSOFT iQ AppPortal
- Ubuntu update for openssl
- Multiple vulnerabilities in Autodesk InfraWorks
- Multiple vulnerabilities in Nessus Network Monitor
- SUSE update for SUSE Manager Client Tools
- Multiple vulnerabilities in IBM Rational Application Developer for WebSphere Software
- Multiple vulnerabilities in IBM Watson Explorer Foundational Components
- Multiple vulnerabilities in IBM i
- Brocade Fabric OS update for OpenSSL
- Gentoo update for IBM Spectrum Protect
- Multiple vulnerabilities in Dell Wyse
- Gentoo update for OpenSSL
- Multiple vulnerabilities in Juniper Networks Steel Belted Radius Carrier Edition
- Multiple vulnerabilities in Dell EMCRecoverPoint
- Multiple vulnerabilities in Dell Hybrid Client
- SUSE update for grafana
- Multiple vulnerabilities in IBM Cognos Analytics
- Buffer overflow in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- SUSE update for openssl-1_1
- SUSE update for openssl-1_1
- SUSE update for SUSE Manager Client Tools
- Multiple vulnerabilities in HPE HP-UX Using OpenSSL
- Multiple vulnerabilities in IBM Security Verify Information Queue
- Multiple vulnerabilities in IBM Security Verify products
- Multiple vulnerabilities in Dell Client Platform
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM Netcool Operations Insight
- Multiple vulnerabilities in Dell PowerScale OneFS
- SUSE update for Security Beta update for SUSE Manager Client Tools and Salt
- SUSE update for Security Beta update for SUSE Manager Client Tools
- Multiple vulnerabilities in IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data
- openEuler update for OpenSSL
- Multiple vulnerabilities in IBM Db2 Rest
- Multiple vulnerabilities in IBM Security Verify Access
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Multiple vulnerabilities in Dell RecoverPoint Classic
- Multiple vulnerabilities in IBM Watson Studio on Cloud Pak for Data
- Multiple vulnerabilities in Dell PowerProtect Data Manager
- Astronomer with IBM update for OpenSSL