QID 198310
Date Published: 2021-03-26
QID 198310: Ubuntu Security Notification for Openssl Vulnerability (USN-4891-1)
It was discovered that OpenSSL incorrectly handled certain renegotiation ClientHello messages.
A remote attacker could use this issue to cause OpenSSL to crash, resulting in a denial of service, or possibly execute arbitrary code.
Solution
Refer to Ubuntu advisory USN-4891-1 for affected packages and patching details, or update with your package manager.
Vendor References
- USN-4891-1 -
usn.ubuntu.com/4891-1/
CVEs related to QID 198310
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| USN-4891-1 | 18.04 (bionic) on src | libssl1.1 |
|
| USN-4891-1 | 20.04 (focal) on src | libssl1.1 |
|
| USN-4891-1 | 20.10 (groovy) on src | libssl1.1 |
|