QID 198310

Date Published: 2021-03-26

QID 198310: Ubuntu Security Notification for Openssl Vulnerability (USN-4891-1)

It was discovered that OpenSSL incorrectly handled certain renegotiation ClientHello messages.

A remote attacker could use this issue to cause OpenSSL to crash, resulting in a denial of service, or possibly execute arbitrary code.

  • CVSS V3 rated as Medium - 5.9 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Refer to Ubuntu advisory USN-4891-1 for affected packages and patching details, or update with your package manager.
    Vendor References

    CVEs related to QID 198310

    Software Advisories
    Advisory ID Software Component Link
    USN-4891-1 18.04 (bionic) on src libssl1.1 URL Logo launchpad.net/ubuntu/+source/openssl/1.1.1-1ubuntu2.1~18.04.9
    USN-4891-1 20.04 (focal) on src libssl1.1 URL Logo launchpad.net/ubuntu/+source/openssl/1.1.1f-1ubuntu2.3
    USN-4891-1 20.10 (groovy) on src libssl1.1 URL Logo launchpad.net/ubuntu/+source/openssl/1.1.1f-1ubuntu4.3