9.8
CVE-2021-3711
- EPSS 87.82%
- Veröffentlicht 24.08.2021 15:15:09
- Zuletzt bearbeitet 21.11.2024 06:22:12
- Erkennungen
SM2 Decryption Buffer Overflow
In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this function twice. The first time, on entry, the "out" parameter can be NULL and, on exit, the "outlen" parameter is populated with the buffer size required to hold the decrypted plaintext. The application can then allocate a sufficiently sized buffer and call EVP_PKEY_decrypt() again, but this time passing a non-NULL value for the "out" parameter. A bug in the implementation of the SM2 decryption code means that the calculation of the buffer size required to hold the plaintext returned by the first call to EVP_PKEY_decrypt() can be smaller than the actual size required by the second call. This can lead to a buffer overflow when EVP_PKEY_decrypt() is called by the application a second time with a buffer that is too small. A malicious attacker who is able present SM2 content for decryption to an application could cause attacker chosen data to overflow the buffer by up to a maximum of 62 bytes altering the contents of other data held after the buffer, possibly changing application behaviour or causing the application to crash. The location of the buffer is application dependent but is typically heap allocated. Fixed in OpenSSL 1.1.1l (Affected 1.1.1-1.1.1k).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Debian ≫ Debian Linux Version 10.0
Debian ≫ Debian Linux Version 11.0
Netapp ≫ Active Iq Unified Manager Version - SwPlatform vmware_vsphere
Netapp ≫ Active Iq Unified Manager Version - SwPlatform windows
Netapp ≫ Clustered Data Ontap Version -
Netapp ≫ Clustered Data Ontap Antivirus Connector Version -
Netapp ≫ E-series Santricity Os Controller Version >= 11.0 <= 11.50.2
Netapp ≫ Hci Management Node Version -
Netapp ≫ Manageability Software Development Kit Version -
Netapp ≫ Oncommand Insight Version -
Netapp ≫ Oncommand Workflow Automation Version -
Netapp ≫ Santricity Smi-s Provider Version -
Netapp ≫ Snapcenter Version -
Netapp ≫ Storage Encryption Version -
Oracle ≫ Communications Cloud Native Core Unified Data Repository Version 1.15.0
Oracle ≫ Communications Session Border Controller Version 8.4
Oracle ≫ Communications Session Border Controller Version 9.0
Oracle ≫ Communications Unified Session Manager Version 8.2.5
Oracle ≫ Communications Unified Session Manager Version 8.4.5
Oracle ≫ Enterprise Communications Broker Version 3.2.0
Oracle ≫ Enterprise Communications Broker Version 3.3.0
Oracle ≫ Enterprise Session Border Controller Version 8.4
Oracle ≫ Enterprise Session Border Controller Version 9.0
Oracle ≫ Health Sciences Inform Publisher Version 6.2.1.1
Oracle ≫ Health Sciences Inform Publisher Version 6.3.1.1
Oracle ≫ Jd Edwards Enterpriseone Tools Version < 9.2.6.3
Oracle ≫ Jd Edwards World Security Version a9.4
Oracle ≫ Mysql Connectors Version <= 8.0.27
Oracle ≫ Mysql Enterprise Monitor Version <= 8.0.25
Oracle ≫ Mysql Server Version >= 5.7.0 <= 5.7.35
Oracle ≫ Mysql Server Version >= 8.0.0 <= 8.0.26
Oracle ≫ Peoplesoft Enterprise Peopletools Version 8.57
Oracle ≫ Peoplesoft Enterprise Peopletools Version 8.58
Oracle ≫ Peoplesoft Enterprise Peopletools Version 8.59
Oracle ≫ Zfs Storage Appliance Kit Version 8.8
Tenable ≫ Nessus Network Monitor Version <= 5.13.1
Tenable ≫ Tenable.Sc Version >= 5.16.0 <= 5.19.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 87.82% | 0.997 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
https://www.oracle.com/security-alerts/cpuapr2022.html
https://www.oracle.com/security-alerts/cpujan2022.html
https://www.oracle.com/security-alerts/cpuoct2021.html
https://security.netapp.com/advisory/ntap-20240621-0006/
https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf
https://security.gentoo.org/glsa/202210-02
https://security.gentoo.org/glsa/202209-02
https://security.netapp.com/advisory/ntap-20211022-0003/
http://www.openwall.com/lists/oss-security/2021/08/26/2
https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=59f5e75f3bced8fc0e130d72a3f582cf7b480b46
https://lists.apache.org/thread.html/r18995de860f0e63635f3008fd2a6aca82394249476d21691e7c59c9e%40%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/rad5d9f83f0d11fb3f8bb148d179b8a9ad7c6a17f18d70e5805a713d1%40%3Cdev.tomcat.apache.org%3E
https://security.netapp.com/advisory/ntap-20210827-0010/
https://www.debian.org/security/2021/dsa-4963
https://www.openssl.org/news/secadv/20210824.txt
https://www.tenable.com/security/tns-2021-16
https://www.tenable.com/security/tns-2022-02