VDB
BDU%3A2021-03037
BDU%3A2021-03037
PUBLISHED
CVSS 4.300000190734863 MEDIUM
Уязвимость процедуры AVX2 Montgomery библиотеки OpenSSL, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
Risk Scores
CVSS 2.0
4.300000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oracle Corp., Red Hat Inc., Canonical Ltd., Сообщество свободного программного обеспечения, Node.js Foundation, IBM Corp., OpenSSL Software Foundation | API Gateway, Transportation Management, Red Hat Enterprise Linux, Ubuntu, Debian GNU/Linux, Enterprise Manager Ops Center, JD Edwards EnterpriseOne Tools, Tuxedo, PeopleSoft Enterprise PeopleTools, Primavera P6 Enterprise Project Portfolio Management, Communications WebRTC Session Controller, Communications Application Session Controller, Communications Network Charging and Control, Agile Engineering Data Management, Secure Global Desktop, Enterprise Manager Base Platform, Endeca Server, Node.js, MySQL Connectors, Communications EAGLE LNP Application Processor, Communications Operations Monitor, Communications Session Border Controller, Communications Unified Session Manager, Enterprise Communications Broker, Enterprise Session Border Controller, JD Edwards World Security, MySQL Workbench, OSS Support Tools, Communications Diameter Signaling Router, MySQL Server, OpenSSL, Oracle Endeca Information Discovery Studio, MySQL Enterprise Monitor, Communications EAGLE Software | |
| Oracle Corp., Red Hat, Inc., Canonical Ltd., Сообщество свободного программного обеспечения, Node.js Foundation, IBM Corp., OpenSSL Software Foundation | API Gateway, Transportation Management, Red Hat Enterprise Linux, Ubuntu, Debian GNU/Linux, Enterprise Manager Ops Center, JD Edwards EnterpriseOne Tools, Tuxedo, PeopleSoft Enterprise PeopleTools, Primavera P6 Enterprise Project Portfolio Management, Communications WebRTC Session Controller, Communications Application Session Controller, Communications Network Charging and Control, Agile Engineering Data Management, Secure Global Desktop, Enterprise Manager Base Platform, Endeca Server, Node.js, MySQL Connectors, Communications EAGLE LNP Application Processor, Communications Operations Monitor, Communications Session Border Controller, Communications Unified Session Manager, Enterprise Communications Broker, Enterprise Session Border Controller, JD Edwards World Security, MySQL Workbench, OSS Support Tools, Communications Diameter Signaling Router, MySQL Server, OpenSSL, Oracle Endeca Information Discovery Studio, MySQL Enterprise Monitor, Communications EAGLE Software |
Timeline
- Jun 15, 2021 CVE Published
- Sep 23, 2026 Distribution Patch
- Sep 23, 2026 Distribution Patch
- Sep 23, 2026 Distribution Patch
- Sep 23, 2026 Distribution Patch
- Sep 23, 2026 Distribution Patch
- Sep 23, 2026 Distribution Patch
- Sep 23, 2026 Distribution Patch
- Sep 23, 2026 Security Advisory
- Sep 23, 2026 Security Advisory
- Sep 23, 2026 Security Advisory
References
- http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html advisory
- http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html advisory
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html advisory
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html advisory
- http://www.securityfocus.com/bid/102118 url
- http://www.securitytracker.com/id/1039978 url
- https://access.redhat.com/errata/RHSA-2018:0998 url
- https://access.redhat.com/errata/RHSA-2018:2185 url
- https://access.redhat.com/errata/RHSA-2018:2186 url
- https://access.redhat.com/errata/RHSA-2018:2187 url
- https://github.com/openssl/openssl/commit/e502cc86df9dafded1694fceb3228ee34d11c11a url
- https://nodejs.org/en/blog/vulnerability/december-2017-security-releases/ advisory
- https://security.FreeBSD.org/advisories/FreeBSD-SA-17:12.openssl.asc url
- https://security.gentoo.org/glsa/201712-03 url
- https://security.netapp.com/advisory/ntap-20171208-0001/ url
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst03881en_us url
- https://www.debian.org/security/2017/dsa-4065 advisory
- https://www.debian.org/security/2018/dsa-4157 advisory
- https://www.openssl.org/news/secadv/20171207.txt advisory
- https://www.openssl.org/news/secadv/20180327.txt advisory
…and 10 more