FlawAtlas
Search the atlas
USN-4738-1 Not scored

openssl, openssl1.0 vulnerabilities

Paul Kehrer discovered that OpenSSL incorrectly handled certain input lengths in EVP functions. A remote attacker could possibly use this issue to cause OpenSSL to crash, resulting in a denial of service. (CVE-2021-23840) Tavis Ormandy discovered that OpenSSL incorrectly handled parsing issuer fields. A remote attacker could possibly use this issue to cause OpenSSL to crash, resulting in a denial of service. (CVE-2021-23841)

Exploit probability Not scored
Published February 18, 2021
Required by Not available
Last source change April 27, 2026

02 / AFFECTED SOFTWARE

Affected packages

Ubuntu:16.04:LTS openssl

23 explicit affected versions

Ubuntu:18.04:LTS openssl

16 explicit affected versions

Ubuntu:18.04:LTS openssl1.0

9 explicit affected versions

Ubuntu:20.04:LTS openssl

6 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities USN-4738-1

Paul Kehrer discovered that OpenSSL incorrectly handled certain input lengths in EVP functions. A remote attacker could possibly use this issue to cause OpenSSL to crash, resulting in a denial of service. (CVE-2021-23840) Tavis Ormandy discovered that OpenSSL incorrectly handled parsing issuer fields. A remote attacker could possibly use this issue to cause OpenSSL to crash, resulting in a denial of service. (CVE-2021-23841)

View original source

05 / REFERENCES

Further evidence