OpenSSL 1.1.1k update addressing two critical vulnerabilities

A fix release for the OpenSSL 1.1.1k cryptographic library has been made available, addressing two vulnerabilities rated high severity:

  • CVE-2021-3450 — a potential bypass of the certificate authority certificate validation when the X509_V_FLAG_X509_STRICT flag is enabled, which is off by default and used for additional verification of certificates within the chain. This issue was introduced in the OpenSSL 1.1.1h implementation of a new check that prohibits the use of chain certificates containing explicitly encoded elliptic curve parameters.

    Due to a coding mistake, the new check overrode the result of the previous certificate authority certificate validity check. As a result, certificates signed by a self-signed certificate that is not chained in a trust relationship with the certificate authority were treated as fully trustworthy. The vulnerability does not manifest if the 'purpose' parameter is set, which is defaulted in the validation procedures for client and server certificates in libssl (used for TLS).

  • CVE-2021-3449 — potential crash invocation server TLS through the sending of a specially crafted ClientHello message by the client. The issue is related to dereferencing a NULL pointer in the implementation of the signature_algorithms extension. The problem only manifests on servers with TLSv1.2 support and session renegotiation enabled (default on).

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster