An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer dereference will result, leading to a crash and a denial of service attack. A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which is the default configuration). OpenSSL TLS clients are not impacted by this issue. All OpenSSL 1.1.1 versions are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1k. OpenSSL 1.0.2 is not impacted by this issue. Fixed in OpenSSL 1.1.1k (Affected 1.1.1-1.1.1j).

Project Subscriptions

Vendors Products
Checkpoint Subscribe
Multi-domain Management Subscribe
Multi-domain Management Firmware Subscribe
Quantum Security Gateway Subscribe
Quantum Security Gateway Firmware Subscribe
Quantum Security Management Subscribe
Quantum Security Management Firmware Subscribe
Debian Linux Subscribe
Fedoraproject Subscribe
Freebsd Subscribe
Freebsd Subscribe
Web Gateway Subscribe
Web Gateway Cloud Service Subscribe
Active Iq Unified Manager Subscribe
Cloud Volumes Ontap Mediator Subscribe
E-series Performance Analyzer Subscribe
Oncommand Insight Subscribe
Oncommand Workflow Automation Subscribe
Ontap Select Deploy Administration Utility Subscribe
Santricity Smi-s Provider Subscribe
Snapcenter Subscribe
Storagegrid Subscribe
Node.js Subscribe
Openssl Subscribe
Openssl Subscribe
Communications Communications Policy Management Subscribe
Enterprise Manager For Storage Management Subscribe
Essbase Subscribe
Graalvm Subscribe
Jd Edwards Enterpriseone Tools Subscribe
Jd Edwards World Security Subscribe
Mysql Connectors Subscribe
Mysql Server Subscribe
Mysql Workbench Subscribe
Peoplesoft Enterprise Peopletools Subscribe
Primavera Unifier Subscribe
Secure Backup Subscribe
Secure Global Desktop Subscribe
Zfs Storage Appliance Kit Subscribe
Enterprise Linux Subscribe
Jboss Core Services Subscribe
Jboss Enterprise Web Server Subscribe
Rhel Eus Subscribe
Rhev Hypervisor Subscribe
Siemens Subscribe
Ruggedcom Rcm1224 Subscribe
Ruggedcom Rcm1224 Firmware Subscribe
Scalance Lpe9403 Subscribe
Scalance Lpe9403 Firmware Subscribe
Scalance M-800 Subscribe
Scalance M-800 Firmware Subscribe
Scalance S602 Subscribe
Scalance S602 Firmware Subscribe
Scalance S612 Subscribe
Scalance S612 Firmware Subscribe
Scalance S615 Subscribe
Scalance S615 Firmware Subscribe
Scalance S623 Subscribe
Scalance S623 Firmware Subscribe
Scalance S627-2m Subscribe
Scalance S627-2m Firmware Subscribe
Scalance Sc-600 Subscribe
Scalance Sc-600 Firmware Subscribe
Scalance W1700 Subscribe
Scalance W1700 Firmware Subscribe
Scalance W700 Subscribe
Scalance W700 Firmware Subscribe
Scalance Xb-200 Subscribe
Scalance Xb-200 Firmware Subscribe
Scalance Xc-200 Subscribe
Scalance Xc-200 Firmware Subscribe
Scalance Xf-200ba Subscribe
Scalance Xf-200ba Firmware Subscribe
Scalance Xm-400 Subscribe
Scalance Xm-400 Firmware Subscribe
Scalance Xp-200 Subscribe
Scalance Xp-200 Firmware Subscribe
Scalance Xr-300wg Subscribe
Scalance Xr-300wg Firmware Subscribe
Scalance Xr524-8c Subscribe
Scalance Xr524-8c Firmware Subscribe
Scalance Xr526-8c Subscribe
Scalance Xr526-8c Firmware Subscribe
Scalance Xr528-6m Subscribe
Scalance Xr528-6m Firmware Subscribe
Scalance Xr552-12 Subscribe
Scalance Xr552-12 Firmware Subscribe
Simatic Cloud Connect 7 Subscribe
Simatic Cloud Connect 7 Firmware Subscribe
Simatic Cp 1242-7 Gprs V2 Subscribe
Simatic Cp 1242-7 Gprs V2 Firmware Subscribe
Simatic Hmi Basic Panels 2nd Generation Subscribe
Simatic Hmi Basic Panels 2nd Generation Firmware Subscribe
Simatic Hmi Comfort Outdoor Panels Subscribe
Simatic Hmi Comfort Outdoor Panels Firmware Subscribe
Simatic Hmi Ktp Mobile Panels Subscribe
Simatic Hmi Ktp Mobile Panels Firmware Subscribe
Simatic Logon Subscribe
Simatic Mv500 Subscribe
Simatic Mv500 Firmware Subscribe
Simatic Net Cp1243-7 Lte Eu Subscribe
Simatic Net Cp1243-7 Lte Eu Firmware Subscribe
Simatic Net Cp1243-7 Lte Us Subscribe
Simatic Net Cp1243-7 Lte Us Firmware Subscribe
Simatic Net Cp 1243-1 Subscribe
Simatic Net Cp 1243-1 Firmware Subscribe
Simatic Net Cp 1243-8 Irc Subscribe
Simatic Net Cp 1243-8 Irc Firmware Subscribe
Simatic Net Cp 1542sp-1 Irc Subscribe
Simatic Net Cp 1542sp-1 Irc Firmware Subscribe
Simatic Net Cp 1543-1 Subscribe
Simatic Net Cp 1543-1 Firmware Subscribe
Simatic Net Cp 1543sp-1 Subscribe
Simatic Net Cp 1543sp-1 Firmware Subscribe
Simatic Net Cp 1545-1 Subscribe
Simatic Net Cp 1545-1 Firmware Subscribe
Simatic Pcs 7 Telecontrol Subscribe
Simatic Pcs 7 Telecontrol Firmware Subscribe
Simatic Pcs Neo Subscribe
Simatic Pcs Neo Firmware Subscribe
Simatic Pdm Subscribe
Simatic Pdm Firmware Subscribe
Simatic Process Historian Opc Ua Server Subscribe
Simatic Process Historian Opc Ua Server Firmware Subscribe
Simatic Rf166c Subscribe
Simatic Rf166c Firmware Subscribe
Simatic Rf185c Subscribe
Simatic Rf185c Firmware Subscribe
Simatic Rf186c Subscribe
Simatic Rf186c Firmware Subscribe
Simatic Rf186ci Subscribe
Simatic Rf186ci Firmware Subscribe
Simatic Rf188c Subscribe
Simatic Rf188c Firmware Subscribe
Simatic Rf188ci Subscribe
Simatic Rf188ci Firmware Subscribe
Simatic Rf360r Subscribe
Simatic Rf360r Firmware Subscribe
Simatic S7-1200 Cpu 1211c Subscribe
Simatic S7-1200 Cpu 1211c Firmware Subscribe
Simatic S7-1200 Cpu 1212c Subscribe
Simatic S7-1200 Cpu 1212c Firmware Subscribe
Simatic S7-1200 Cpu 1212fc Subscribe
Simatic S7-1200 Cpu 1212fc Firmware Subscribe
Simatic S7-1200 Cpu 1214 Fc Subscribe
Simatic S7-1200 Cpu 1214 Fc Firmware Subscribe
Simatic S7-1200 Cpu 1214c Subscribe
Simatic S7-1200 Cpu 1214c Firmware Subscribe
Simatic S7-1200 Cpu 1215 Fc Subscribe
Simatic S7-1200 Cpu 1215 Fc Firmware Subscribe
Simatic S7-1200 Cpu 1215c Subscribe
Simatic S7-1200 Cpu 1215c Firmware Subscribe
Simatic S7-1200 Cpu 1217c Subscribe
Simatic S7-1200 Cpu 1217c Firmware Subscribe
Simatic S7-1500 Cpu 1518-4 Pn\/dp Mfp Subscribe
Simatic S7-1500 Cpu 1518-4 Pn\/dp Mfp Firmware Subscribe
Simatic Wincc Runtime Advanced Subscribe
Simatic Wincc Telecontrol Subscribe
Sinamics Connect 300 Subscribe
Sinamics Connect 300 Firmware Subscribe
Sinec Infrastructure Network Services Subscribe
Sinec Nms Subscribe
Sinec Pni Subscribe
Sinema Server Subscribe
Sinumerik Opc Ua Server Subscribe
Tia Administrator Subscribe
Tim 1531 Irc Subscribe
Tim 1531 Irc Firmware Subscribe
Sonicwall Subscribe
Capture Client Subscribe
Sma100 Firmware Subscribe
Sonicos Subscribe
Tenable Subscribe
Log Correlation Engine Subscribe
Nessus Network Monitor Subscribe
Tenable.sc Subscribe
Advisories
Source ID Title
Debian DLA Debian DLA DLA-2751-1 postgresql-9.6 security update
Debian DSA Debian DSA DSA-4875-1 openssl security update
EUVD EUVD EUVD-2021-1628 An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer dereference will result, leading to a crash and a denial of service attack. A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which is the default configuration). OpenSSL TLS clients are not impacted by this issue. All OpenSSL 1.1.1 versions are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1k. OpenSSL 1.0.2 is not impacted by this issue. Fixed in OpenSSL 1.1.1k (Affected 1.1.1-1.1.1j).
Github GHSA Github GHSA GHSA-83mx-573x-5rw9 openssl-src NULL pointer Dereference in signature_algorithms processing
Ubuntu USN Ubuntu USN USN-4891-1 OpenSSL vulnerability
Ubuntu USN Ubuntu USN USN-5038-1 PostgreSQL vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
http://www.openwall.com/lists/oss-security/2021/03/27/1 cve-icon cve-icon
http://www.openwall.com/lists/oss-security/2021/03/27/2 cve-icon cve-icon
http://www.openwall.com/lists/oss-security/2021/03/28/3 cve-icon cve-icon
http://www.openwall.com/lists/oss-security/2021/03/28/4 cve-icon cve-icon
https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf cve-icon cve-icon
https://cert-portal.siemens.com/productcert/pdf/ssa-772220.pdf cve-icon cve-icon
https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=fb9fa6b51defd48157eeb207f52181f735d96148 cve-icon cve-icon
https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44845 cve-icon cve-icon
https://kc.mcafee.com/corporate/index?page=content&id=SB10356 cve-icon cve-icon
https://lists.debian.org/debian-lts-announce/2021/08/msg00029.html cve-icon cve-icon
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CCBFLLVQVILIVGZMBJL3IXZGKWQISYNP/ cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2021-3449 cve-icon
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0013 cve-icon cve-icon
https://security.FreeBSD.org/advisories/FreeBSD-SA-21:07.openssl.asc cve-icon cve-icon
https://security.gentoo.org/glsa/202103-03 cve-icon cve-icon
https://security.netapp.com/advisory/ntap-20210326-0006/ cve-icon cve-icon
https://security.netapp.com/advisory/ntap-20210513-0002/ cve-icon cve-icon
https://security.netapp.com/advisory/ntap-20240621-0006/ cve-icon cve-icon
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-openssl-2021-GHY28dJd cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2021-3449 cve-icon
https://www.debian.org/security/2021/dsa-4875 cve-icon cve-icon
https://www.openssl.org/news/secadv/20210325.txt cve-icon cve-icon cve-icon
https://www.oracle.com//security-alerts/cpujul2021.html cve-icon cve-icon
https://www.oracle.com/security-alerts/cpuApr2021.html cve-icon cve-icon
https://www.oracle.com/security-alerts/cpuapr2022.html cve-icon cve-icon
https://www.oracle.com/security-alerts/cpujul2022.html cve-icon cve-icon
https://www.oracle.com/security-alerts/cpuoct2021.html cve-icon cve-icon
https://www.tenable.com/security/tns-2021-05 cve-icon cve-icon
https://www.tenable.com/security/tns-2021-06 cve-icon cve-icon
https://www.tenable.com/security/tns-2021-09 cve-icon cve-icon
https://www.tenable.com/security/tns-2021-10 cve-icon cve-icon
History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: openssl

Published:

Updated: 2024-09-17T03:43:55.497Z

Reserved: 2021-03-17T00:00:00

Link: CVE-2021-3449

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-03-25T15:15:13.450

Modified: 2024-11-21T06:21:33.050

Link: CVE-2021-3449

cve-icon Redhat

Severity : Important

Publid Date: 2021-03-25T00:00:00Z

Links: CVE-2021-3449 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses